ONTAP audit logs forwarded to Splunk server from only one node
Applies to
- ONTAP 9
- Log forwarding
- Syslog server
- Splunk server
Issue
- Splunk server only receives audit logs from one node in the cluster.
- Log forwarding configuration is correct .
- Intercluster LIF policy does not have management-log-forwarding services applied to it.
