Hi splunk god,
Have enquiry, i have an environment which heavyforwarder logs send to cluster indexer. I need the below multi index merge into single index which is index_general. Basically, when user search index_general and able to search all the logs contain in the three index.
1)Is this configuration feasible?
index_fw->index_general index_window->index_general index_linux->index_general 2)If yes, this configuration needs to be done on HF or Indexer? 3)if qns2 yes, which config file should be configured.
... View more