15-Oct-2021 13:49
I've added another Splunk instance to my existing remote logging profile and the changes aren't being applied since no logs are reaching the new server. I checked over and over that the IP/port was correct and that the profile was associated with a virtual server/security policy whose traffic was being logged locally and on my existing Splunk instance.
After scratching my head several times, I tried removing the working/currently functioning Splunk IP from the same remote logging profile. I saved the change and even verified it was sync'd to the standby device. Still, logs were being sent to the instance that I removed.
Has anyone else experienced this type of issue - where saved changes weren't being applied?
Tired of scratching my head.
Thanks!
Tone