You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Dec 14, 2024. It is now read-only.
I am in a situation where Im re-engineering alot of our splunk instance (splunk cloud)
We have the PA addon on our Heavy forwarder but it was never configured. We also have it on our SH again not configured.
So, Since the logs are currently going through our heavy forwarder via a syslog (universal forwarder) do I configure the Addon on (account, log lvl etc.) on Just the heavy forwarder or do I need to duplicate that config in the addon on our search head?
Note only the app is installed on both our regular splunk SH and our ES search head.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
-
I am in a situation where Im re-engineering alot of our splunk instance (splunk cloud)
We have the PA addon on our Heavy forwarder but it was never configured. We also have it on our SH again not configured.
So, Since the logs are currently going through our heavy forwarder via a syslog (universal forwarder) do I configure the Addon on (account, log lvl etc.) on Just the heavy forwarder or do I need to duplicate that config in the addon on our search head?
Note only the app is installed on both our regular splunk SH and our ES search head.
Beta Was this translation helpful? Give feedback.
All reactions