of course, keep in mind I'm not all that familiar with splunk config. This splunk infrastructure was passed down to me. I installed PureStorage app and the TA. They were installed on a indexer and heavy forwarder, our infrastructure consists of 6 indexers, 6 search heads, 1 cluster master, 1 deployment server, and 2 heavy forwarders. To answer your inputs question, how do I look that up? is it under the installed app (inputs.conf). Where do I look for issues in the logs? is it the ones in splunkhome/var And, yes...I can see the data on the appliances and splunk would just feed off of that I suppose
... View more