i did run config and i did configure the URI but I'm not sure how this works? the URI is for the mongoDB server IP? or where to poll the IOCs from the tool?
A little background, i have mongoDB in a different server - not in the search head like the docs recommend. I don't know how the communication work between the mongoDB, splunk and the tool where the IOCs are located. if you can help me understand that flow will be great.
thanks and I'm sorry for my novice in this regards.