Hi @gcusello , Ain't sure if we missed any step, the thing is, the UF was already installed in the AD machine, so could it be that the AD machine is sending the logs correctly to the Splunk machine, but the last doesn't then have any index set up since the reinstallation ? If so (or otherwise and we're missing some point) is there any step by step guide on how to set up an indexer to receive the logs ? Many thanks.
... View more