To enhance your DataSync integration for Splunk Enterprise, you can optionally configure the Splunk meshlet to keep track of the data you are sending by using index numbers in case of data loss. The HTTP Event Collector in the Splunk server supports indexer acknowledgement, a feature that will index each data that are sent.
First, you will need to contact Perspectium Support to get you started with Splunk meshlet.
To get started with using indexer acknowledgment, complete the following procedures:
|