This is only a remark.
I had to change this line in the ossec_agent_management.xml to have my OSSEC Server field not empty.
| inputlookup lookup_ossec_servers | search managed=1
| ossecservers managed
I saw many user on the web last few moths that had the same issue.
unable to run data collection??? maybe he have the same
Splunk doesn't seem to like that custom search command when populating the search.
The populating search has been changed in version 1.1.85 of the Splunk for OSSEC app.