Splunk Dev

I can see data in logs but not in index for http event collector

Amandeepsin
New Member

I can see http_event_collector_metrics.log logs under

$SPLUNK_HOME/var/log/introspection/splunk/

But splunk says latest event received was 2 days ago. Whats going wrong in http event collector as I cannot see data if I select index after 7th of may. Previous data is available

Tags (1)
0 Karma
1 Solution

PowerPacked
Builder

Hi @Amandeepsin

The _introspection index data is splunk's internal metrics regarding HEC performance and connection.

You need to check the own index into which the data is coming in.

Here is the sample event.

alt text

Thanks

View solution in original post

0 Karma

PowerPacked
Builder

Hi @Amandeepsin

The _introspection index data is splunk's internal metrics regarding HEC performance and connection.

You need to check the own index into which the data is coming in.

Here is the sample event.

alt text

Thanks

0 Karma

Amandeepsin
New Member

Hi,

Latest event to that own index which is mentioned in HEC source is 2 days ago. But in _introspection I can see events.

Any comments!!

Thanks,

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...