Splunk Dev

I can see data in logs but not in index for http event collector

Amandeepsin
New Member

I can see http_event_collector_metrics.log logs under

$SPLUNK_HOME/var/log/introspection/splunk/

But splunk says latest event received was 2 days ago. Whats going wrong in http event collector as I cannot see data if I select index after 7th of may. Previous data is available

Tags (1)
0 Karma
1 Solution

PowerPacked
Builder

Hi @Amandeepsin

The _introspection index data is splunk's internal metrics regarding HEC performance and connection.

You need to check the own index into which the data is coming in.

Here is the sample event.

alt text

Thanks

View solution in original post

0 Karma

PowerPacked
Builder

Hi @Amandeepsin

The _introspection index data is splunk's internal metrics regarding HEC performance and connection.

You need to check the own index into which the data is coming in.

Here is the sample event.

alt text

Thanks

0 Karma

Amandeepsin
New Member

Hi,

Latest event to that own index which is mentioned in HEC source is 2 days ago. But in _introspection I can see events.

Any comments!!

Thanks,

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...