Hi,
I have this props and transforms file to filter out the events before they reach the indexqueue. Not sure but the filter doesn't seem to work any more.
When I use btools to check the configurations, I still notice the configuration in place.
We recently upgraded Splunk version to 9.0.4 from 8.1.0 a month ago to check if this has some effects on the configurations but it doesn't have any
What could be the reason