Dear all,
I have configured the HTTP Event Collector but can't successfully send events.
My configuration in inputs.conf
[http]
allowSslCompression = true
allowSslRenegotiation = true
dedicatedIoThreads = 2
disabled = 0
enableSSL = 0
index = ffjj
maxSockets = 0
maxThreads = 0
sslVersions = *,-ssl2
_rcvbuf = 1572864
host = splunk-dev
port = 8088
sourcetype = R_LICENCIE_TEMP
useDeploymentServer = 1
[http://appmobile]
disabled = 0
host = splunk-dev
index = appmobile
indexes = appmobile
sourcetype = _json
token = 03F50C74-121B-4FBF-9999-ACB9A032AD02
sourcetypeSelection = From List
I have created a very basic request
{
"time": 1433188255,
"event": {
"membre_no" : 1213,
"est_membre": 1
}
}
I know Splunk receives the message but it throws an error 503 "Server is busy"
{
"text": "Server is busy"
"code": 9
}
my request is being sent to http://:/services/collector/event
I have deactivated SSL in the HTTP Event Collector configuration. I know it is taken into account because if activated, there server doesn't reply.
I would like to investigate but :
1. I can't find anyone having the same issue as me - no topic relates to 503 - "server is busy"
2. I don't know how to increase log level for HTTP Event collector. Setting this category `category.HttpEventCollector=DEBUG` doesn't provide more logs (and I update the rootCategory level as well)...
3. I know the parsing is being performed by Splunk because as soon as I change the JSON format to something malformed, I get another error
Can you please let me know what's going on and how I can have logs?
Thank you in advance for your help.
Eric
↧