If you're on Cloud, you can't send your syslog directly to cloud and need a local forwarder (or SC4S instance) anyway. So it doesn't matter much whether it's TCP or UDP (at least in terms of on-site vs. Cloud).
... View more
When you are updating to 9.0.4+ or at least 9.0.5 this adding version string to dashboards/forms should be happening automatic. Some older version 9.0.4 etc. have some issues with some special tags etc. You could get more information from slack https://splunk-usergroups.slack.com/archives/C03M9ENE6AD
... View more
Not to revive this old thread, but to folks who visit this later with a similar question, the following app will do what OP is asking for: https://splunkbase.splunk.com/app/5237/
... View more