Hi Everyone,
I am using Splunk enterprise free version and it stops every hour and gives me "missing or malformed messages.conf stanza AUDIT :start_of_event_drops ", knowing that I don't use universal forwarder.
Any solutions?