We have a windows forwarder running on vm02, and forwarding data to vm01 which is the main Splunk Enterprise.
we configured the inputs and props.conf in the vm02 forwarder level, so far we are able to search the events in vm01, coming from the vm02. But when we go to sourcetypes or inputs link in the vm01 GUI. We dont see any sourcetypes or inputs that are configured at forwarder level. But we are able to search the events using the forwarder sourcetypes in the vm01.
How to make vm01 GUI to show the vm02 sourcetypes and inputs ?
↧