Hi all,
I have the stream Addon with almost 12 forwarders.
Here i created a group under the stream distrubuted forwarderManagement, I gave the regex which matches to forwarders.
But only few servers are pointing to this new group, rest of them are pointing to default group.
I see all error under status of the servers which are pointing to default group. restarted the splunk services, updated inputs.conf. nothing worked, please help me in this!! if anyone is aware.
Thanks.
Did you ever get the answer why clients were becoming members of defaultgroup?
Are you using Splunk Cloud