The forwarder and app has been installed and configured as shown in the instructions. The apps configuration settings cannot detect all the logs currently coming into Splunk. It detects some of the data inputs but not all. Is there a specific location I need to check to update this? Or am I missing some configuration step? The forwarder is monitoring the relevant location where all the logs sit.
Have you checked the eventtypes? The app relies heavily on them and by default these don't always point to the correct indexes where your data is located.