splunk / splunk-ansible

Ansible playbooks for configuring and managing Splunk Enterprise and Universal Forwarder deployments

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

outputs.conf must be created before ftr

mikedickey opened this issue · comments

Submitted by @rfaircloth-splunk

Splunk indexes events immediately on startup this is causing events that should be on the indexer to be found on the local buckets of the SH in the SHC and CM/LM outputs.conf must be generated before splunk is started