I am pretty new to Splunk and my project is also new. Can someone please explain the configurations given in our cluster manager. We have a syslog server which receives logs from F5 WAF devices and UF in syslog server forwards the data to our cluster manager.
Hi
Based on these conf files it seems to do next.
More detailed information from those links which @PaulPanther add in his post.
r. Ismo
Check out following helpful docs and specifications files 😉
How Splunk Enterprise handles your data - Splunk Documentation