I deployed the Tomcat Add-On for Splunk. It's currently running on both my indexer and search head.
It's working without issue on the indexer. But it's not displaying the data in the correct format on the search head. And I'm not sure what to do to fix this issue:
I've checked to make sure the data is in the correct format for the forwarder
I've checked the permissions on the server, they're correct
I've recreated my environment to spec...
I've done everything except get the bloody thing to work. I need help.