After installing SA-Faroo and supplying the appropriate API key, why does the following message appear in the Splunk search window?
"The external search command 'faroo' did not return events in descending time order, as expected."
Interesting question, brodsky.
To fix, in the app, copy commands.conf from default to local. Then add the line "overrides_timeorder = true" at the end. No restart is necessary.
[faroo]
filename = faroo.py
streaming = true
passauth = true
overrides_timeorder = true