Getting Data In

SC4S: parsing_err="Incorrect index, index='main'"

pepitogrillospl
Loves-to-Learn Lots

Hi all,

I've setup am SC4S just to forward nix:syslog events.

In local/context/splunk_metadata.csv:

nix_syslog,index,the_index
nix_syslog,sourcetype,nix:syslog

Cant find the events inSplunk and splunkd.log is filling with:

12-29-2023 09:52:50.993 +0000 ERROR HttpInputDataHandler [2140 HttpDedicatedIoThread-0] - Failed processing http input, token name=the_token, channel=n/a, source_IP=172.18.0.1, reply=7, events_processed=1, http_input_body_size=1091, parsing_err="Incorrect index, index='main'"

The HEC probes at sc4s boot are successful and inserted in the correct index.

Any help would be really appreciated.

Thank you

Daniel

Labels (1)
0 Karma

pepitogrillospl
Loves-to-Learn Lots

Hi,

If I recall correctly at HEC token creation do not select any index , use  local/context/splunk_metadata.csv for that. I think that fixed it.

Daniel

0 Karma

GetAGrip1011
New Member

That makes sense.  Thank you for replying.  Do you have an example splunk_metadata.csv file?  The Splunk documentation mentions separating items by vendor/type, but they do not mention where to find those. 

 

0 Karma

GetAGrip1011
New Member

Did you ever figure out a solution to this?  Running into the same problem.  Seems that there is an issue with where the HEC key points, and the actual index that gets populated. 

 

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...