Do i have to configure the inputs.conf on the IDX clusters?
This is what i currently have, but there is a communication error between the SH and the IDX_Cluster:
[indexAndForward]
index = true
[tcpout]
defaultGroup = idx-indexers
forwardedindex.filter.disable = false
indexAndForward = 1
[tcpout]
forwardedindex.0.whitelist = .*
forwardedindex.1.blacklist = _.*
forwardedindex.2.whitelist = (_internal)
[tcpout:idx-indexers]
autoLBFrequency = 40
disabled = 0
server = :9997,:9997:9997
sslCertPath = $SPLUNK_HOME/etc/auth/server.pem
sslPassword =
sslRootCAPath = $SPLUNK_HOME/etc/auth/cacert.pem
sslVerifyServerCert = 0
useACK = 1
Anything im doing wrong here?
... View more