Getting Data In

Logs not flowing to splunk index from GCP -Solution

splunkeremy
Engager

Hi Everyone!.

I'm here to share the resolution for one of the frequent errors that we see in internal logs and sourcetype=splunkd.

If you happen to encounter the below error,

"Failed processing http input , token name=token_name,parsing_err="Incorrect index", index=index_name"

Please make sure that your index name is being added to the respective token(HEC).

In order to avoid this error, make sure your index is added under the respective token as soon as a new index is created.

[https://token name]

disabled = 0

index=default_index name

indexes=index1,index2, index3;[add your index here]

 

Cheers

 

 

 

Labels (1)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...