Hi,
I just installed Splunk and got my HEC working. I want to view the individual events that I have passed into the HEC. Is that possible?
Thanks!
-s.
Search for index=that_index
.
If you didn’t specify an index when you configured the HEC input, then try index=main
You can try index=* to see which indexes you have any log. After that use index=selected_one