Files
Splunk_Docker/files/splunk-etc/apps/SplunkDeploymentServerConfig/default/outputs.conf
Brett Woodruff 28c8d411ad Inital Commit
2024-06-13 15:48:26 -04:00

13 lines
432 B
Plaintext

# Version 9.2.2.20240415
[tcpout]
forwardedindex.2.whitelist = (_audit|_internal|_introspection|_telemetry|_metrics|_metrics_rollup|_configtracker|_dsclient|_dsphonehome|_dsappevent)
# If you have configurations to forward the internal logs to other instances,
# please include the following settings to make sure the deployment server logs
# are indexed locally.
#
# [indexAndForward]
# index = true
# selectiveIndexing = true