Splunk Dev

HEC random issue

smalonso
Explorer

Hello,

I'm using HEC to send data to our splunk cloud instance in _json format. Currently I have 2 pods - 1 HEC - 2 indexes architecture.
I do a "transaction" and I have 3 splunk JSON events going one to indexA and the 2 others to indexB.

Randomly I'm getting an error
{"type":"INTERNAL","description":"error during post to splunk for tenantId=monitoring err=StatusCodeError: 400 - {\\"text\\":\\"Incorrect index\\",\\"code\\":7,\\"invalid-event-number\\":1}"},

However indexes are correct as I see events on them. For example in the log sample above I have only one event in indexB (Where I should have 2) and one in indexA. Sometimes is one event failing, sometimes 2, and sometimes is one index and sometimes is the other.

In introspection index I see parse error is 1, however I don't know where I can see a more detailed explanation.
I've already check HTTP collector troubleshooting page, again I'm in splunk cloud with no access to config files, so I'm kind of block.

Can someone help me to either to know how to get more information or share if you've faced a similar issue?

0 Karma

smalonso
Explorer

Hello, for anyone interested and update on this issue:

The problem happens when using 1 server - 2 HEC - 4 indexes (2 for each HEC)
I made a few tests such as

  • 2 pod - 1 HEC - 4 indexes
  • 2 pods - 2 HEC - 2 indexes (Only one index per HEC)

In both cases the issue is not present. I couldn't find the reason yet.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...