I have DBX currently on a standalone splunk install (acting as both SearchHead and Indexer). I need to be able to send DB data retrieved via DBX to multiple indexers (not just the splunk instance that DBX is installed on). How is this configured ?
Well, the easiest way to do that would be to set up distributed search on the other search head(s) so that they also search this indexer.
An example will make this clearer, I hope:-)
Indexer A
Indexer B
Search Head C
On either B or C (or both), you can configure Distributed Search. It's in the Splunk Manager UI.
Go to Distributed Search Setup - by default it is turned on; if it is on, you can leave everything at the defaults.
Go to Search Peers and Add New. Enter the info for Indexer A.
Wait a few minutes and then run a search on B or C - whichever you set up - and you should see the data from Indexer A.