I used this command to configure splunk forwarder using cli
splunk add monitor d:\logs -Follow-only True
I got no errors but I don't see any changes in my input.conf
I tried add the m...
Hello everyone!
In this scenario i have one Heavy forwarder and one indexer cluster (of course the is a Cluster Manager over there).
The HF have some inputsconfigured in this way (inputs...
I've installed the Proofpoint TAP SIEM Add-on version 1.3.140, and I'm trying to configure a modular input on my heavy forwarder under "Settings" -> "Data Inputs" -> "P...
...onventions and I have to create three source types based on that. How should I do it? Should I create separate configuration files (props and inputs) inside the local folder and assign 3 s...
...et to "true", audit events are sent to the indexQueue.
* If set to "false", you must add an inputs.conf stanza to tail the
audit log for the events reach your index.
* Default: true My q...
...d input in this Add-on on Core SH but it is not reflecting on ES SH.
1. So Input(MSCS-Addon) configuration also reflecting in both SH's if we configured only on one SH's?
2. If not then we configure...
...estination. So far I have come to the conclusion that the audit criteria should be:
1) that inputs.conf includes all necessary logfiles and that disable = 0 for each,
2) that outputs.conf is s...
Hi All, seeking help on this! For POC purpose I was trying to configure the google.com home page into Splunk website inputs app, when Defining CSS selector ,under the page preview tab google.com p...
Due to some issue, We have to discontinue our existing Heavy Forwarder and move all the sources, data inputs, Splunk TA Apps/add-on one new server where we have already installed Heavy forwarder.
B...