I am also digging into this. It is helpful to know that with newer Splunk stuff it has been moved to a different website. How to prepare TLS certificates for use with the Splunk platform | Splunk Docs looks like Splunk changed how some of the stuff works in 9.4 - 10. That being said the above link is a good way to verify if your pem files are correct. Currently we are stuck on the: SAN OtherName not found for configured OIDs in client certificate CertBasedUserAuth: error fetching username from client certificate
... View more
Hi @SPL_Dummy , no, you can set the rendexXml option true or false for an input and not for a part of it. To use this Correlation Search, create a new one clonit it and modifying the sourcetype contained in the macros. Ciao. Giuseppe
... View more