Getting Data In

Http Event Collector output not being indexed?

arun_kant_sharm
Path Finder

alt text

Hi Experts,
I configured HEC input, after that I run curl command using that token, it returns {"text":"Success","code":0}.
But no event comes into my INDEX.
Any suggestions on how to proceed?
Thanks in advance.

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Can you please change sourcetype from _json to json_no_timestamp for "test" token and try again?

View solution in original post

harsmarvania57
Ultra Champion

Hi,

Can you please change sourcetype from _json to json_no_timestamp for "test" token and try again?

arun_kant_sharm
Path Finder

Thanks, its working 🙂

0 Karma

harsmarvania57
Ultra Champion

Great, I have converted my comment to answer so you can accept it.

0 Karma

renjith_nair
Legend

@arun_kant_sharma,

Have you searched in the default index which you have configured while creating the token ?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

arun_kant_sharm
Path Finder

Actually I created the HEC input in a Index(Test) , so nothing is come in default index.

0 Karma

renjith_nair
Legend

Even for "All Time" time range?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...