# If you want to see the log information of your hydra # workers on your search head uncomment the lines below. # Splunk by default will suppress the _internal events from # being forwarded, this removes that suppression. # [tcpout] # forwardedindex.3.whitelist = _internal