I've installed the Proofpoint TAP SIEM Add-on version 1.3.140, and I'm trying to configure a modular input on my heavy forwarder under "Settings" -> "Data Inputs" -> "P...
...d input in this Add-on on Core SH but it is not reflecting on ES SH.
1. So Input(MSCS-Addon) configuration also reflecting in both SH's if we configured only on one SH's?
2. If not then we configure...
I used this command to configure splunk forwarder using cli
splunk add monitor d:\logs -Follow-only True
I got no errors but I don't see any changes in my input.conf
I tried add the m...
...igure out is where the configuration file containing the directory that is being monitor is stored. I looked in etc/system/local/inputs.conf, but the values were not there. Any other thoughts? I'm p...
Indexers are NOT configured for SSL input.
05-01-2019 09:15:44.740 -0500 INFO TcpOutputProc - Initializing connection for non-ssl forwarding to indexer_design.com:9997
05-01-2019 09:15:44.740 -0...
Hi, I just installed a index cluster and i already know that i shoud place Apps to $SPLUNK_HOME/etc/master-apps/ directoty at my manager node to distribute it accross all indexers but i have 2 q...
...hat. However, I cannot send HTTP because the HEC is set for HTTPS input and so is getting rejected by the Splunk HEC. Is there a way to have the HEC collect BOTH HTTP and HTTPS and set the r...
I have a stats table in a dashboard and I'm trying to configure the drilldown to run a search that takes a multivalued field as input.
So If I click on a row that has field A="a","b","c", I want t...
Hi Splunkers, I'm performing some test on my test environment and I'm curious about observed behavior. I want to add some network inputs, so tcp and udp ones, to my env. I found easily on doc how t...
I want to configure CRC Salt but I am quite not sure how write it on inputs.conf. The directory on splunk is like this: /home/csaops/csasec/NFV/KPG_MIO_HC_Logs_2021-11-10-10.txt How do I configure...