Yes, I have already created output.conf file and added the required info.
It is placed under the etc/system/local/ folder.
[tcpout]
defaultGroup = default-autolb-group
indexAndForward = 0
negotiateProtocolLevel = 0
sslCommonNameToCheck = *.<<stack>>.splunkcloud.com
sslVerifyServerCert = true
useClientSSLCompression = true
[tcpout-server://inputs1.<<stack>>.splunkcloud.com:9997]
[tcpout-server://inputs2.<<stack>>.splunkcloud.com:9997]
[tcpout-server://inputs14.align.splunkcloud.com:9997]
[tcpout:default-autolb-group]
disabled = false
server = 54.85.90.105:9997, inputs2.<<stack>>.splunkcloud.com:9997, inputs3.<<stack>>.splunkcloud.com:9997, .....
inputs15.<<stack>>.splunkcloud.com:9997
[tcpout-server://inputs15.<<stack>>.splunkcloud.com:9997]
sslCommonNameToCheck = *.<<stack>>.splunkcloud.com
sslVerifyServerCert = false
sslVerifyServerName = false
useClientSSLCompression = true
autoLBFrequency = 120
[tcpout:scs]
disabled=1
server = stack.forwarders.scs.splunk.com:9997
compressed = true
... View more