Hello,
We are in the process of setting up a Spunk 6.2.3 distributed environment with a dedicated search head, indexer and deployment server. We installed enterprise Splunk on all three servers and applied the license but not sure what to do next. Is there a way to configure the servers for their specific roles and remove unnecessary ones? We couldn't find step-by-step instructions in the Splunk documentation. Thanks!
I have the same question and been looking for an answer from books, training courses, and community, but no luck. Basically, it's how to setup a Splunk distributed environment.
You can find step-by-step instructions in the Distributed Search manual.
http://docs.splunk.com/Documentation/Splunk/6.2.3/DistSearch/Whatisdistributedsearch
You can also find wizards, warlocks, trolls, and goblins in the #splunk IRC channel on EFnet. We are more than happy to help you out in person, and to take your gold.
*gold = not real gold. No one does that anymore. We won't take anything. But you will leave satisfied.