Hi Guys,
This is most likely a silly question but I can get this add on to work. I have a Splunk cluster and my understanding is this add-on gets pushed out to the Universal Forwarders and the send in the converted log.
I get the log but its just a straight string, No formating, nothing.
Can anyone explain where this should be installed?
Thanks, Anmol Patel
I will get back to you soon if that works. Appreciate the help
@bobinnz refer to this doc, it lists out thee context on how and where to deploy the add-on based on the content.
https://docs.splunk.com/Documentation/AddOns/released/Overview/Wheretoinstall