Well, it can be several things, network/config: You have shown the inputs but what about the outputs? Obviously, you will have a better understanding of your network / access / data flow details,...
See more...
Well, it can be several things, network/config: You have shown the inputs but what about the outputs? Obviously, you will have a better understanding of your network / access / data flow details, but here's a number of area's for you to check and investigate. Have you installed the Splunk Cloud UF App Package onto the HF (splunkclouduf.spl This contains the outputs.conf / TLS config, you download this from your Splunk cloud stack). Have you allowed the HF for outbound connectivity to Splunk Cloud (Firewall changes) ? After you download and install the Splunk Cloud UF App Package onto the HF, can you see the HF's _internal logs in Splunk cloud? In Splunk cloud there is allow IP whitelisting feature, have you configured this for the HF to allow data to be sent to Splunk cloud?