If Splunk Universal Forwarders are configured with compressed = true in the outputs.conf, can the Cribl Stream SplunkTCP source receive from them properly?
Solved
SplunkTCP Source with UF using compress=true
Best answer by Clint Sharp
Compression is not supported. See How to Architect Your LogStream to LogStream Data Flows for a good overview of features support.
Also, this was discussed in this thread in the Slack community: Slack.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
