Getting Data In

Why is the Http event collector not visible in UI?

ArunSudarsanam1
Explorer

Hi,

Splunk version : 6.6.1

Http event collector not visible in UI, we are not able to find it under data inputs.

After searching in support site, we have modified input config file.(disabled=0) and done server restart.

Still we cannot see Http event collector option under data inputs.

1 Solution

jcrabb_splunk
Splunk Employee
Splunk Employee

The Data Inputs page should look something like this:

alt text

If you are missing one or more inputs, this is typically related to an older app breaking some gui elements. I've seen it with older DBConnect (dbx-2207) as well as a number of third party apps on 6.3.x and newer. There were code changes to the gui in 6.3 and apps which aren't supported in 6.3.x or later can cause this behavior. Hopefully this is what you are experiencing and a simple upgrade to can correct it for you. I would review all installed apps and confirm you have the latest version installed. If it doesn't support the version you are on, remove it temporarily and see if that resolves your issue.

Jacob
Sr. Technical Support Engineer

View solution in original post

Marcussafar
New Member

We are also having this same issue. Already had the edit_http_token capability for my role, that was not a fix.

We are running Splunk 7.0.3 and CentOS 7.4

Seems like a major bug.,I am also having this issue. Running splunk 7.0.3 on CentOS 7.4.

Seems like there is a major bug.

0 Karma

dajomas
Path Finder

I found the culprit!

I don't know how or when it happened but in my role, the "edit_token_http" capability was disabled.

After I (re-)enabled it, the HTTP Event Collector was available again in the Data Inputs screen

dajomas
Path Finder

I have the same issue. I have removed every (yes every) app I installed but to no avail. I also made sure that Index Clustering and Distributed Search was disabled. But alas, no HTTP Event Collector is available in my Data Inputs.

I am running Splunk 7.2.0 Enterprise on Centos 7.5

In the past, I was able to configure HEC and they are still running and active but without the option in Data Inputs, I cannot manage them nor add or delete them via the Splunk UI

(When I do a clean install, there is no issue but migrating is not my preferred choice)

Does anybody have a tip on where to look to fix this issue?

0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

The Data Inputs page should look something like this:

alt text

If you are missing one or more inputs, this is typically related to an older app breaking some gui elements. I've seen it with older DBConnect (dbx-2207) as well as a number of third party apps on 6.3.x and newer. There were code changes to the gui in 6.3 and apps which aren't supported in 6.3.x or later can cause this behavior. Hopefully this is what you are experiencing and a simple upgrade to can correct it for you. I would review all installed apps and confirm you have the latest version installed. If it doesn't support the version you are on, remove it temporarily and see if that resolves your issue.

Jacob
Sr. Technical Support Engineer

ArunSudarsanam1
Explorer

Hi,

We have splunk_app_db_connect v3.1.1 still we are not able to see HTTP event collector in Data inputs GUI.

Inside settings and data inputs we can see only types listed excluding HTTP event collector.
We cannot see local inputs and forwarded inputs in our splunk.

0 Karma
Get Updates on the Splunk Community!

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...