We were facing issue in Splunk log forwarding to IDXer cluster.
I found that our enterprise instance servers are 6.5.3 and UFs were of 6.6.2. So I uninstalled 6.6.2 version of UF and reinstalled 6.5.2 version on the same machine.
Then I did the similar configuration on the new UF. Now in the logs I can see UF is connected to Indexer but no data is been forwarded to the enterprise version.
I feel there is something I missed during the reinstallation.
Thanks.
Vikram.
↧