A customer would like to remove the output_file capability from users with the default user role to stop
them from filling up the disk on the search head with lookup files. What is the best way to remove this
capability from users?
A customer has a number of inefficient regex replacement transforms being applied. When under heavy
load the indexers are struggling to maintain the expected indexing rate. In a worst case scenario, which
queue(s) would be expected to fill up?