Hi All,
I need to configure the one Splunk server as Search head and another 2 standalone machines as indexers in distributed environment.
Can some one guide me how I can do that.
I already installed the Splunk enterprise on my Unix machine and its up and running but I am not sure how I can make that to work as search head and point the other 2 machine as indexers machine to this search head.
Please help me.
This is a pretty broad topic but I would recommend reviewing the following document which will guide you with configuring a distributed environment: