Hi guys,
i have been working on the creation of a deployment server with universal forwarders, and the outputs.conf contains:
[tcpout]
defaultGroup=cm
[tcpout:cm-processing]
server=cm:9997
This is making its way to the universal forwarder, but when I run ./splunk list forward-server it shows the connection as inactive. I have looked on the distribution server for clients, which returned this machine as a client. Also, I have checked the listener (cm) to see if it has forwarders attached which it doesnt. Any help would be greatly appreciated, Thanks!
... View more