Hi
I have a similar issue. I do not see HTTP Event Collector, under data inputs.
/opt/splunk/etc/apps/splunk_httpinput/default
inputs.conf
$ more inputs.conf
[http]
disabled=1
port=8088
enableSSL=1
dedicatedIoThreads=2
maxThreads = 0
maxSockets = 0
useDeploymentServer=0
I have the same version in non prod but the only difference is, prod is a search head cluster and non prod has only one search head.
It is available in non prod, the file contents of inputs.conf are the same.
What needs to be modified in inputs.conf?
Change disabled=1 > disabled=0