Hello,
I have Splunk Stream app installed on my Search Head (Deployment Server) which controls the Stream Forwarders deployed on my Indexers (Deployment Clients).
Even though app is deployed and I receive stream data, whenever I change the configuration of my streams (remove fields from protocols, add IP blacklist filters etc) the configuration does not get applied on Stream Forwarders even though I have tried to restart them. No IP filtering is applied nor protocol fields are removed.
Any way I can troubleshoot that?
Thanks
Chris