Ayush, Thank you for these suggestions. Regards the deployment server it suggests you can set up a universal forwarder on a windows server to forward direct to Splunk Cloud that shouldn't need an enterprise Splunk to act as a deployment server is this correct? Or does the Cloud version become the deployment server in this scenario? Checked the logs and actually ma seeing loads of below errors appearing. 04-23-2021 16:46:07.058 +0100 INFO DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected Will try and test telnet connectivity next week as will need to open up ports and install. splunk list forward-server Active forwards: inputs.prd-p-vk6k0.splunkcloud.com:9997 (ssl) Configured but inactive forwards: prd-p-vk6k0.splunkcloud.com:9997 splunk show deploy-poll Deployment Server URI is set to "prd-p-vk6k0.splunkcloud.com:8089". splunk list monitor Monitored Directories: $SPLUNK_HOME\var\log\splunk C:\Program Files\SplunkUniversalForwarder\var\log\splunk\audit.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\btool.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\conf.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\dfm_stderr.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\dfm_stdout.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\first_install.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\health.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\license_usage.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\metrics.log.1 C:\Program Files\SplunkUniversalForwarder\var\log\splunk\mongod.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\remote_searches.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\scheduler.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\search_messages.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\searchhistory.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd-utility.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd_access.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd_ui_access.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\wlm_monitor.log $SPLUNK_HOME\var\log\splunk\license_usage_summary.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\license_usage_summary.log $SPLUNK_HOME\var\log\splunk\metrics.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\metrics.log $SPLUNK_HOME\var\log\splunk\splunk_instrumentation_cloud.log* C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunk_instrumentation_cloud.log $SPLUNK_HOME\var\log\splunk\splunkd.log C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log $SPLUNK_HOME\var\log\watchdog\watchdog.log* C:\Program Files\SplunkUniversalForwarder\var\log\watchdog\watchdog.log $SPLUNK_HOME\var\run\splunk\search_telemetry\*search_telemetry.json $SPLUNK_HOME\var\spool\splunk\...stash_new Monitored Files: $SPLUNK_HOME\etc\splunk.version D:\IBM\WebSphere\AppServer\profiles\AppSrv01\logs\PELMAX761DEVSVR\SystemErr.log D:\IBM\WebSphere\AppServer\profiles\AppSrv01\logs\PELMAX761DEVSVR\SystemOut.log D:\IBM\WebSphere\AppServer\profiles\Dmgr01\logs\dmgr\SystemErr.log D:\IBM\WebSphere\AppServer\profiles\Dmgr01\logs\dmgr\SystemOut.log
... View more