I have installed Splunk App for Stream on the Search head and Splunk TA stream on Universal forwarder.
Also installed Splunk TA stream on the Indexer.
Now I need to extract the payload data also. I am trying enable it, however, nothing working.
What is the CLI option to enable payload extraction on UF and to be visible on SH?
↧