We plan to move our Splunk enterprise to Aws. The plan is to use a forwarder (from a local windows machine) to collect the data (around 15 mb a month) and send it to the indexer on aws.
I am trying to work on the forwarder - aws connection part, but i am getting a time out error.
My forwarder outputs.conf file looks like this :
tcpout-server = amazon server:9997
sslcertpath =localpath /certificate.pen
I don't know what values to use for sslpassword and sslrootcapath.
I have also enabled the indexer to listen to 9997 port.
Where i am going wrong ?
... View more