Hi, I am collecting event from UF to IDX. Sometimes events are missing due to network issue btw UF and IDX.
So I am trying to use persistent queue.
Now I am seeing this manual : https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Usepersistentqueues
I would like to write missing event on UF's disk when the network connection is disconnected.
And when the connection becomes normal, I want to forward those written event on disk to IDX.
Then, do I have to below inputs.conf setting on UF? or IDX?
[tcp://9994]
persistentQueueSize=100MB
Please help me out.