Hi All,
I have integrated Splunk HEC with springboot .when i hit application and checked in splunk am unable to see logs in splunk search with given index .am using source type as log4j2
Can any one help me .
Thanks in advance
Looks like an ingestion problem, not a search problem. You'll get better information by moving this to Getting Data In. Do you have any log indicating that HEC ingestion happened?
I can only say to review logs on both the sender side and splunkd.log. My only experience with HEC is from Puppet's Splunk HEC app, and the only thing I had to figure out was how to force HEC to offer outdated SSL algorithm. (Not the app's fault, just to be clear.) It is hard to read error messages that don't tell you how to solve. But no error message would make it much harder - and absence of error remains a possibility. That's why I suggested Admin forum.