Hello Community, I would like to inquire about some issues I am facing while setting up a heavy forwarder in splunk. Please take a look at the below issues :- 1) Hosts are visible in splunk but all of them are not forwarding their logs to the indexer. 2) Linux server are not able to forward logs to the indexer. 3) Some host are able to forward their logs to indexer post a modification in their universal forwarder file manually, but it takes an hour or so before they forward their logs. 4) The most recently added do not show their logs in real time i.e. when a time frame recently added devices should logs in last 4 hours or 60 minutes but they do show only post 24 hours time filter. Thanks in advance.
... View more