If you cannot use Server Classes in Splunk Light, how else are you supposed to configure Data Inputs without editing conf files or using the CLI? Say I make a Server Class called "Windows Servers" and I add the 5 hosts I have Universal Forwarders on to the group, and then configure "Windows Servers" to monitor Event Logs. Now I add a 6th Windows host and install a Universal Forwarder on it. How can I start collecting Event Logs if I cannot edit the Server Class "Windows Servers" to add this host to it?
The only way I see how is to configure the Universal Forwarder on install to add the monitor (which introduces its own problems), edit the inputs.conf on the forwarder, or edit the conf files on the Splunk server.
All of these solutions are super cumbersome and defeat the purpose of trying to manage things using the web console. Between this and 2-3 other "Splunk Light" specific bugs I have run into during my testing, Splunk Light seems like a half-baked, incomplete solution.
... View more