Hi, i have a problem with sending one index from indexer cluster to another standalone Splunk instance. I have a 4 indexers, replication factor = 3 . How should I configure my cluster to send only 1 index? I tried to install UF on indexer and monitor the index directory. The event was in wrong format. Also tried to configure forwarding all events in indexer to standalone splunk, and then filter to receive only one index. But nothing came of it.
We decided to make a standalone instance to be searchhead. And then make a user, with access to only one index
We decided to make a standalone instance to be searchhead. And then make a user, with access to only one index