Splunk DB Connect seems to save "tail_rising_column_checkpoint_value" in inputs.conf, and it doesn't seem to be replicated in a search head cluster environment. When I look at the DB Input in the UI on each Search Head, they show different checkpoint values.
Should I whitelist inputs.conf for clustering to solve this, or how is this supposed to work?
please open a support ticket.