Hi Splunkers
I currently have one Splunk machine that has two rules at once (a search head and an indexer) and I want to separate each rule from another with its own separate machine.
Is there a way to do such action? if so, what are the steps to do so?
Thanks.
Hi @muradgh,
you have to:
for more information you can see at https://docs.splunk.com/Documentation/Splunk/9.0.2/DistSearch/Whatisdistributedsearch
Ciao.
Giuseppe
Hi @muradgh,
you have to:
for more information you can see at https://docs.splunk.com/Documentation/Splunk/9.0.2/DistSearch/Whatisdistributedsearch
Ciao.
Giuseppe
Thank you @gcusello ^^
Hi @muradgh,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉