Hi Splunk experts!
We have a Splunk Enterprise Search Head Cluster with 3 Search Heads.
We need more cores, so we're adding a 4th physical server.
Is there anything special we need to do besides give it the same config as the other Search Heads? This is the first time since we built the Search Head Cluster that we have added an additional Search Head into it.
Thanks!
... View more
Hi Splunk Community,
Can one configure inputs.conf to forward events based on a "Custom Views" in Event Viewer?
Specifically, we are looking to forward the events Certification Authority events.
Thanks
... View more
We have this problem too. Member servers forward their Security log just fine. It does not work on Domain Controllers.,We have the same (or similar) problem. Member servers forward their Security Event Log events just fine. Domain Controllers do not.
... View more