I am new to splunk, and need help configuring the log files collected from my honeypot to monitoring VM. They are on the same network and can ping each other. The source is acknowledged via the splunk dashboards, but not sure which VM I am supposed to edit the input and output configuration files and any other edits.
Hi
here is some good starting point to your journey with Splunk:
Happy Splunking
r. Ismo