As a pretty new user, I recently installed the Universal Forwarder on a Linux server, created a file input, and forwarded to an indexer. This was working fine. Then as a result of a support case, I had to change the role from a UF to a Search Head in Distributed Search. After doing this and configuring the SH to forward its logs to the indexer, I am unable to return any results with a simple index=_internal search. Yet I can get results from all the non-internal indexes just fine. I have another SH (non-clustered) that works, and I have closely compared the Roles, but found no differences.
After searching the forum, I found a number of references to outputs.conf - here's mine:
[indexAndForward]
index = false
[tcpout]
defaultGroup = indexer
forwardedindex.filter.disable = true
indexAndForward = false
Not sure what else to look for?
... View more