All I want to do is to use the filtering functionality on the Splunk Light Forwarder without having to enable the Heavy Forwarder, as most features are disabled in the Splunk Light Forwarder as stated here: http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Forwardercapabilities
I would still like to use the Splunk Light Forwarder but enable the filtering feature only, Can this be done, if so then how?
I do recall that there was a way to enable this on a Splunk Light Forwarder, as this functionality is actually disabled and not removed, so enabling it should be possible.
Well I decided to the the filtering from the Splunk SearchHead/indexer side, passing the logs through using a Splunk Light Forwarder.
Ill leave this question as a reference for others who may search for the same questions.
Thanks anyways Splunkers
So your saying there is absolutely no way to enable filtering on a Splunk Light Forwarder at all?, cause its just disabled and not removed, so Im sure there is a way to enable this disabled functionality.