After I ticked "Enable Indexer acknowledgement" in "HTTP Event Collection" -> "Auto Generated ITSI Event Management Token", I no longer have notable events generated. And I saw "Data channel is missing" errors in _internal index.
After some research, I understood from https://docs.splunk.com/Documentation/Splunk/8.2.7/Data/AboutHECIDXAck that HEC sender must include a channel identifier. But how do I configure ITSI so that it include channel identifier when it is generating notable events?
Thank you very much.