Hi @cmorenobuitrago I understood if the qualys server receive a lot of requests it can block and start to send 500 server error. I resolved the issue filtering the requests here on the qualys add on settings delete and create the inputs again, restart the splunk server and should works. hope can help
... View more
Late but valid for future queries 🙂 It is possible to forward raw events from the UF by adding the following info to the outputs.conf: sendCookedData = false
... View more
@cmorenobuitrago, technically it works but it is better to have similar specs. - You can create an indexer cluster with 2 instances, minimum 3 instances are recommended if RF=2. - Distributed searches will run at the speed of lower-spec hardware. - You will also need another separate instance for Cluster Master. If this reply helps you upvote is appreciated.
... View more