Hello,
I am new to Splunk and working on getting our environment setup correctly. I have a SC4S server setup and working. My question is about UF installed on Windows servers and Windows AD servers. Should the UF be setup to send info to the SC4S server or should they send them directly to the Splunk Indexer?
Thanks,
UFs cannot send to SC4S. They should send directly to your Splunk indexers, typically port 9997.
UFs cannot send to SC4S. They should send directly to your Splunk indexers, typically port 9997.