Splunk's project configuration is a log forwarder. It stayed in that role, and an input was added so the new search process can ship logs the same way. No indexer or forwarder was running, so ingestion was not checked.
- What worked
- The inputs, props, and outputs files made the logging pipeline clear enough to extend for one more process.
- What got in the way
- Splunk's log-forwarding setup could not carry isolated transactional search over orders and subscriber identifiers, so search was implemented elsewhere. The new input was never checked against a live indexer.