DerekB,
Can you share Splunk configuration details for Forwarding all data from Splunk Indexer to QRadar ?
Will, having just the outputs.conf work?
outputs.conf
[tcpout]
defaultGroup = SIEM_12345
indexAndForward = true
disabled = false
[tcpout:SIEM_12345]
server = SIEM_IP:12345
compressed = true
sendCookedData = true
... View more