Hi i have installed the Cacti Mirage Add-On for Splunk on my lab instance which is Search Head and indexer in one.
Cacti is installed in /var/www/html/cacti-1.0.1/
I have installed the Universal Forwarder on cacti and am seeing data for the following sourcetypes coming in to my index called cacti:
However some of the reports are missing data - i think because my lookup table is not being populated.
Looking at the search for Cacti Polling & Lookups Status the search is driven by:
eventtype=cacti:mirage | timechart span=5m count by host