Hi Jerry, in that case where TA is installed on both Indexer and SH, Where the data input and all configurations are to be configured- on SH right (for Splunk Cloud deployment) below flow? Data sources --> HF(Syslog server) (TA not required)--> Cloud indexer (with TA)--> Cloud SH(with TA) I'd also suggest if you could update the add-on documentation to include clear details pls. That would help. I have Splunk cloud with ITSI (not ES) and I want to test the Fortinet Add-on
... View more