I'm fetching only internal logs for UF in my single box of Splunk Enterprise which acts as search head and DS too.
May I know that only fetching internal logs of UF will be enough to get the reports and alerts from DMC ????
To only monitor within aspects of UF.
The Monitoring Console (MC) only uses internal logs for its reports and dashboards.
View solution in original post