@Vardhan Thank you so much for your time I am really happy here are the steps find the result 1.Install Splunk AWS add-on in Search Head 2.Create outputs.conf in search head directory (/opt/Splunk/etc/apps/splunk_apps_aws/local/ vi output.conf) 3. Enter the following content in output.conf ([indexAndForward] index = false # Turn off indexing on the search head [tcpout] defaultGroup = my_search_peers # Name of the search peer group forwardedindex.filter.disable = true indexAndForward = false [tcpout:my_search_peers] server=10.10.10.1:9997,10.10.10.2:9997,10.10.10.3:9997 # list of peers)
... View more