I have inherited a Splunk Enterprise deployment with a mixed OS (Windows/Linux) environment. We are in the process of converting this to a full linux instance and want to leave the Hybrid instance behind. Could someone provide me a link to a step-by-step configuration process for setting up the following:
A Search Head Cluster (3 search heads)
Indexer Cluster (5 indexers). - NOTE: This is already functioning in the old instance, so I believe I can figure this one out. However, I just want to ensure this is done right.
We already have a Deployment server in place and 4 Heavy forwarders. My biggest concern is setting up the search head cluster since we do not currently have this implemented. Any help will be greatly appreciated.