It seems that I am stuck with HEC, here is answer, that I got from official Splunk Support:
I you need to use HEC, events need to be contained in one request:
"Events must be contained within a single HTTP request. They cannot span multiple requests."
as explained in the official documentation:
https://docs.splunk.com/Documentation/Splunk/7.2.5/Data/FormateventsforHTTPEventCollector#Raw_event_parsing
I'll try if it's possible to use TCP input for these logs. I will let this issue opened for updates.
Thank you for your help
... View more