Hi All,
I'm bit new with Splunk. I'm trying to ingest CiscoAMP logs using Cisco AMP for Endpoints App. I have installed the App on Heavy Forwarder and configured it with API client and ID.
However, I'm not able to create new input because I'm getting the following error.
when I checked the status of the KVStore on HF it was failed.
Please assist me in fixing this, Thanks
Regards,
Inayath
Hi @Inayath,
on Heavy Forwarders and Indexers, Splunk Professional Services hint to disable KV-Store to consume less memory for a not used feature.
Ciao.
Giuseppe