Hello, I have Splunk Enterprise v8.1 in distributed cluster with 1 SH, 1 master, 2 indexers and 2 heavy forwarders. I have Cisco security suite installed on the HF and the data visualization is displaying correctly. I am looking for assistance to display the data in the SH. cisco devices send logs to HF. HF is configured to route traffic to indexers and all is working fine. Search results showed up on SH but can’t get the Cisco security suite app to display the data. Any help would be greatly appreciated. Thanks!
... View more