We have the TA installed on the search head as well as the heavy forwarder. The EC2 build roles on each server have the same policy attached that allows them to ingest our AWS information. When configuring the accounts and inputs on the HEC, we get no data. If I configure it on the search head we can get the data, but thats not the best practice.
I cannot see in the installation docs anywhere where is specifies how this is supposed to work.
↧