I have a Splunk (Enterprise) PROD system and I need to figure out the connectivity between the various components.
I have managed to figure out the components - 3 Search Heads + 6 indexers + many forwarders.
(Query used: | rest /services/server/info | dedup splunk_server,server_roles | table splunk_server,server_roles)
I do not have access to the conf files, limited access to REST services, and full access to _internal files.
Can you please tell me how to figure out the connectivity from the internal log files? Do each of the Splunk components log anything each time they connect?