Hi again, note that I am using the Splunk home page to set the parameters, I am not editing the conf files directly.
There are 2 inputs.conf files 1 in etc\system\local (which has [default} and host = mypc) the other (later) in \etc\apps\search\local (which is empty).
props.conf (2 copies, this is the latest in time) -
[first_install-too_small]
PREFIX_SOURCETYPE = True
SHOULD_LINEMERGE = False
is_valid = True
maxDist = 9999
[export_metrics-too_small]
PREFIX_SOURCETYPE = True
SHOULD_LINEMERGE = False
is_valid = True
maxDist = 9999
transforms.conf is rather large and I cannot see any specific areas modified when I set up the Data Input.
There does not appear to be a restart command that I can run from a command prompt.
I believe the 'restriction' is more fundamental, is the Light version of Splunk limited to only listening for local clients (and refuses external clients), whereas the Enterprise version allows external clients?
I deleted and re-established the Data Input and restarted the PC, the outcome was the same.
Regards
Active
... View more