Getting Data In

SC4S: parsing_err="Incorrect index, index='main'"

pepitogrillospl
Loves-to-Learn Lots

Hi all,

I've setup am SC4S just to forward nix:syslog events.

In local/context/splunk_metadata.csv:

nix_syslog,index,the_index
nix_syslog,sourcetype,nix:syslog

Cant find the events inSplunk and splunkd.log is filling with:

12-29-2023 09:52:50.993 +0000 ERROR HttpInputDataHandler [2140 HttpDedicatedIoThread-0] - Failed processing http input, token name=the_token, channel=n/a, source_IP=172.18.0.1, reply=7, events_processed=1, http_input_body_size=1091, parsing_err="Incorrect index, index='main'"

The HEC probes at sc4s boot are successful and inserted in the correct index.

Any help would be really appreciated.

Thank you

Daniel

Labels (1)
0 Karma

pepitogrillospl
Loves-to-Learn Lots

Hi,

If I recall correctly at HEC token creation do not select any index , use  local/context/splunk_metadata.csv for that. I think that fixed it.

Daniel

0 Karma

GetAGrip1011
New Member

That makes sense.  Thank you for replying.  Do you have an example splunk_metadata.csv file?  The Splunk documentation mentions separating items by vendor/type, but they do not mention where to find those. 

 

0 Karma

GetAGrip1011
New Member

Did you ever figure out a solution to this?  Running into the same problem.  Seems that there is an issue with where the HEC key points, and the actual index that gets populated. 

 

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...