Getting Data In

HTTP Event collector

rahul2gupta
Path Finder

Hi  @gcusello ,

I am curious to know why I am able to see  HTTP Event collector under the Data Inputs on my Indexer where there is no HTTP Event collector on Search Head.

Indexer

rahul2gupta_0-1640162779167.png

 

Search Head

rahul2gupta_1-1640162819996.png

Regards,

Rahul Gupta

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Apart from @gcusello already said (that you see available input types; notice that count for most of them is zero), your deployment seems strange.

You have webui enabled on indexers - that's not very usual. In case of a cluster you typically deploy config with apps cluster-wide.

And you have inputs defined on search-head. That's also not very typical. I'd set up a heavy forwarder for that and leave search heads to do searching.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rahul2gupta,

In the available Data Inputs you have all the possible ones even if not enabled, but what's the problem?

could you better describe your architecture?

You have some Indexers and one or more Search Heads.

Then you enabled HEC Collector on one of your servers, which one: IDX, SH or HF?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...