The documentation shows that a Netcool flat file gateway is needed. I am assuming the netcool flat file gateway will produce a file that will be ingested by the forwarder. How does Splunk know to automatically the schema changes for alerts.status?
↧