Hello I need an urgent help. I created HEC data inputs. I did follow these guidelines. https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/HECExamples https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/UsetheHTTPEventCollector The test was success and I'm able to get {"text": "Success", "code": 0} However, the index was still empty which I'm expecting it should contains the message data. What would be the reason? Our Splunk Deployment is like below 1 Searchead Instance 2 Indexer Instance 4 Forwarder Instance. I created the HEC on Searchead via GUI. Please help to advice and thanks in advance
... View more