Getting Data In

SC4S: parsing_err="Incorrect index, index='main'"

pepitogrillospl
Loves-to-Learn Lots

Hi all,

I've setup am SC4S just to forward nix:syslog events.

In local/context/splunk_metadata.csv:

nix_syslog,index,the_index
nix_syslog,sourcetype,nix:syslog

Cant find the events inSplunk and splunkd.log is filling with:

12-29-2023 09:52:50.993 +0000 ERROR HttpInputDataHandler [2140 HttpDedicatedIoThread-0] - Failed processing http input, token name=the_token, channel=n/a, source_IP=172.18.0.1, reply=7, events_processed=1, http_input_body_size=1091, parsing_err="Incorrect index, index='main'"

The HEC probes at sc4s boot are successful and inserted in the correct index.

Any help would be really appreciated.

Thank you

Daniel

Labels (1)
0 Karma

pepitogrillospl
Loves-to-Learn Lots

Hi,

If I recall correctly at HEC token creation do not select any index , use  local/context/splunk_metadata.csv for that. I think that fixed it.

Daniel

0 Karma

GetAGrip1011
New Member

That makes sense.  Thank you for replying.  Do you have an example splunk_metadata.csv file?  The Splunk documentation mentions separating items by vendor/type, but they do not mention where to find those. 

 

0 Karma

GetAGrip1011
New Member

Did you ever figure out a solution to this?  Running into the same problem.  Seems that there is an issue with where the HEC key points, and the actual index that gets populated. 

 

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...