All,
Does anyone have a walk through on setting up the time center on Splunk ES for Linux (centOS 7 in this case) hosts? I have the time.sh input from SPlunk_TA_nix going but doesn't work out of the box. Other NTP app on splunkbase don't even have tags/eventtypes that I looked at. Any direction on here would be great.