When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?

When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
A . Enable indexer acknowledgment.
B . Enable forwarder acknowledgment.
C . splunk check-integrity -index <index name>
D . index=_internal component=ACK | stats count by host

Answer: A

Explanation:

Per the provided Splunk reference URL https://docs.splunk.com/Documentation/Splunk/8.0.5/Data/AboutHECIDXAck

"While HEC has precautions in place to prevent data loss, it’s impossible to completely prevent such an occurrence, especially in the event of a network failure or hardware crash. This is where indexer acknolwedgment comes in."

Reference https://docs.splunk.com/Documentation/Splunk/8.0.5/Data/AboutHECIDXAck

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments