Issue
Druva Add-on not sending logs into Splunk
Resolution
Enable the option 'Enable Events Export' for 'ALL EVENTS'.
Action Plan:
Navigate to the Endpoint/Saas app.
On the Endpoints/SaaS Apps console, Click the gear for Endpoints & SaaS Apps Settings.
Under 'Event API Settings' click on 'Edit'.
Ensure the option 'Enable Events Export' is checked and 'Categories to export' has 'ALL EVENTS'.
5. If you see anything else, such as 'Backup & Restore' within 'Categories to Export,' click on X to show All Events. Then click on Save.
6. Leave the default SYSLOG facility of 23.
Note : Please give at least 24 hours to generate Events to export.