Oct 15, 2021

Remote logging profile changes not being applied

I've added another Splunk instance to my existing remote logging profile and the changes aren't being applied since no logs are reaching the new server. I checked over and over that the IP/port was correct and that the profile was associated with a virtual server/security policy whose traffic was being logged locally and on my existing Splunk instance.


After scratching my head several times, I tried removing the working/currently functioning Splunk IP from the same remote logging profile. I saved the change and even verified it was sync'd to the standby device. Still, logs were being sent to the instance that I removed.


Has anyone else experienced this type of issue - where saved changes weren't being applied?


Tired of scratching my head.





