@codebuilder I'm (very) new to Splunk. How does one do this: Update the pass4SymmKey in outputs.conf by adding the non-hashed, plain text key, then cycle the forwarder daemon. Where do I get the non-hashed, plain text key? Also is the forwarder daemon just "splunk" on the forwarder machine? Thanks, Chris
... View more