Apparently enabling LWF turns off udp input. What are the step steps to enable it?
Run the command
./splunk enable module input/UDP input/UDP enabled.
You need to restart the Splunk Server for your changes to take effect.
You should instead enable it by creating a conf file default-mode.conf
containing:
[pipeline:udp]
disabled = false
Which version does this apply to? I ran it in 4.1.5 and Splunk returns a message that the command is deprecated:
sh-3.2# ./splunk enable module input/UDP This command is deprecated.
see other answer
Run the command
./splunk enable module input/UDP input/UDP enabled.
You need to restart the Splunk Server for your changes to take effect.