Giuseppe, This is an app I installed from Splunkbase and it runs on a heavy forwarder. I don't know if it uses a KV-Store, if the stream is deleted once it is received on the OCI side, or if the checkpoint is in a file on the HF. The app did not have its own inputs screen, instead you had to add it under data inputs and scrolli until you found that entry. It does use a .pem file to make an API connection, but there is no way to know if a checkpoint is in play or not let alone what type. I have not been able to reach the developer, but in all fairness, I only have their old splunk.com address and not their new Cisco address (which is different then what their Splunk one was since I received an NDR attempting to send it to the Cisco domain) so the message may not have been received.
... View more