Hi,
i'm evaluating splunk and have very simple configuration - central splunk + number of light forwarders. The problem is that data from forwarder appears in central server ~30 mins after it appears in logs that are scanned by forwarder. What might be cause?
thanks.