I have set up a new splunk test environment with search head cluster (3 SH) and index cluster (2 IDX).
Also added Splunk_SA_CIM first in version 4.18, in my latest test version 4.20.2.
Splunk is working fine, acclerated DM are working, which means they are searchable.
After installing the sophos Central app https://splunkbase.splunk.com/app/6186/ I'm not able to search in my datamodel:
| datamodel Authentication search
More simple:
searching with tag is not working, index=* tag=authentication has the same error.
Tested on a single splunk without problems.
??
Has anyone solved running the app succesfully on a splunk cluster system?
More information:
splunk installation version 8.1.4
even the configuration within the app sophos central for loglevel, proxy, settings and the input are not propagated automatically to the other search heads in the cluster.