Hello,
I have 3 servers, Search Head, Indexer, Deployment Server,
According to the manual:
Installed Splunk add-on for Unix and Linux on all 3 servers.
Manual says to enable data and scripted inputs.
In my Deployment Server:
I enabled all the File and Directory Inputs, Scripted Inputs, and the Scripted Event Inputs.
Questions:
Do I have to enable all the inputs on my Search Head and Indexer too?
If I enable the inputs in these 2 servers, will there be replicated data, or conflicts?
Thanks
... View more