Getting Data In

Where does the HEC data gets stored ?

surekhasplunk
Communicator

I have HTTP event collector well configured using token from a client. 

Now i want to understand where does these json format events gets stored? 

I mean the exact json logs which are coming via HEC, are they stored somewhere in our splunk environment ? 

Labels (1)
Tags (1)
0 Karma
1 Solution

ak9092
Path Finder

@surekhasplunk if you're asking if some file is created in Splunk environment before indexing the events coming over HEC, then that's not the case as i believe HTTP events directly gets indexed to the specified index name in the input stanza.

 

 

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust
HEC stores data in your Splunk indexes.
---
If this reply helps you, Karma would be appreciated.

ak9092
Path Finder

@surekhasplunk if you're asking if some file is created in Splunk environment before indexing the events coming over HEC, then that's not the case as i believe HTTP events directly gets indexed to the specified index name in the input stanza.

 

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

the one can also define used (or want to use) index on HEC json.

https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/FormateventsforHTTPEventCollector

For that reason it's good to define allowed / used index on inputs.conf per used token.

And of course the one must first define used indexes on indexers otherwise events goes to the last change index which is usually main-index.

r. Ismo

isoutamo
SplunkTrust
SplunkTrust

Hi

Usually in inputs.conf there are definitions under every input stanza in which indexes events can and/or must stored. 

See more from https://docs.splunk.com/Documentation/Splunk/8.0.4/Data/UsetheHTTPEventCollector

r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...