Getting Data In

Http Event Collector output not being indexed?

arun_kant_sharm
Path Finder

alt text

Hi Experts,
I configured HEC input, after that I run curl command using that token, it returns {"text":"Success","code":0}.
But no event comes into my INDEX.
Any suggestions on how to proceed?
Thanks in advance.

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Can you please change sourcetype from _json to json_no_timestamp for "test" token and try again?

View solution in original post

harsmarvania57
Ultra Champion

Hi,

Can you please change sourcetype from _json to json_no_timestamp for "test" token and try again?

arun_kant_sharm
Path Finder

Thanks, its working 🙂

0 Karma

harsmarvania57
Ultra Champion

Great, I have converted my comment to answer so you can accept it.

0 Karma

renjith_nair
Legend

@arun_kant_sharma,

Have you searched in the default index which you have configured while creating the token ?

Happy Splunking!
0 Karma

arun_kant_sharm
Path Finder

Actually I created the HEC input in a Index(Test) , so nothing is come in default index.

0 Karma

renjith_nair
Legend

Even for "All Time" time range?

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...