Hello,
I am still fairly new to Ironstream for Splunk. We are looking to change how we have Splunk set up on our different systems and I'm trying to figure out if we actually need the SSDFHFS file mounted, and if so, in what mode.
The documentation says Ironstream needs the SSDFHFS file when using IDT, DCE, and Log4j appender.
I have no idea of what those things are or when they would be used.
I currently have Ironstream for Splunk installed with the SDFAPI, SDFLOG, SDFSMF, and SDFSYS forwarder tasks running.
Do any of those tasks make use of IDT, DCE, or the Log4j appender? I'm thinking not, but I really don't know that much about Ironstream. I basically just installed it and set up the started tasks for someone else that was more familiar with Ironstream.
If IDE, DCE, or the Log4j appender are not being used, can I get by without mounting the SSDFHFS file system?
Thank you,
------------------------------
Alan Jones
FIDELITY NATIONAL INFORMATION SERVICES INC
LITTLE ROCK AR
------------------------------