Getting Data In

Http Event Collector output not being indexed?

arun_kant_sharm
Path Finder

alt text

Hi Experts,
I configured HEC input, after that I run curl command using that token, it returns {"text":"Success","code":0}.
But no event comes into my INDEX.
Any suggestions on how to proceed?
Thanks in advance.

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Can you please change sourcetype from _json to json_no_timestamp for "test" token and try again?

View solution in original post

harsmarvania57
Ultra Champion

Hi,

Can you please change sourcetype from _json to json_no_timestamp for "test" token and try again?

arun_kant_sharm
Path Finder

Thanks, its working 🙂

0 Karma

harsmarvania57
Ultra Champion

Great, I have converted my comment to answer so you can accept it.

0 Karma

renjith_nair
Legend

@arun_kant_sharma,

Have you searched in the default index which you have configured while creating the token ?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

arun_kant_sharm
Path Finder

Actually I created the HEC input in a Index(Test) , so nothing is come in default index.

0 Karma

renjith_nair
Legend

Even for "All Time" time range?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...