hi @gcusello , I do have both indexer and heavy forwarder in my testing environment, may I ask if you mean all index-time operation conf. file is better put in Indexer or Heavy Forwarder? As both of my conf. files mentioned above are put under the path of /etc/apps in Search Head. Here are some of my logs: type=USER_END msg=audit(xxxxxxxxxxxx) source = /var/log/audit/audit.log <- log to keep type=CRED_DISP msg=audit(xxxxxxxxxx) source = /var/log/audit/audit.log <-log to eliminate I am trying to eliminate all logs other than (type=USER_*), where [type] is the interesting field. Sorry for the messy elaboration.
... View more