The CLI command " Splunk add forward-server indexer: < receiving-port > " is used to define the indexer and the listening port on forwards. The command creates this kind of entry " [tcpout-server:// < ip address > : < port > ] " in the outputs.conf file.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit