Hi Guys, We am running in the similar issues. We are collecting windows security, registry changes & linux auth logs using UF which forwards data to IUF and then to Splunk Cloud indexers. The issue is we have the logs sources located in multiple geo location and each geo location has local IUF's hosted. However, we see some of the sources windows/linux servers are showing data in future. How do we solve this?
... View more