I hope this could help you out.
Most Common Implementation and Deployment Framework
Install splunk enterprise on license master and configure license master
Install splunk enterprise on indexers and configure indexers (alternatively for indexer cluster, install Splunk enterprise on cluster master and indexers and configure indexer cluster)
Install splunk enterprise on search heads and configure search heads
Install splunk enterprise on deployment server and configure deployment server
Install splunk universal forwarder on input devices and configure universal forwarders to connect to deployment server and to forward to indexers
Install Splunk enterprise on DMC monitoring console server and configure monitoring console
(Optional) – Install Splunk enterprise on heavy forwarders and configure heavy forwarders
Install and Configure Splunk Indexer
Install Splunk Enterprise on Linux Server (If you need to create a Linux Server first, visit ___)
Configure Splunk Instance to be an Indexer
Connect Splunk Indexer to Splunk Search Head (Must Configure Search Headfirst, see instructions here)
Peer Splunk Indexer to DMC (Monitoring Console) for monitoring
... View more
I think this might be helpful.
=DATE(2015, 5, 20) - returns a serial number corresponding to 20-May-2015.
=DATE(YEAR(TODAY()), MONTH(TODAY()), 1) - returns the first day of the current year and month.
=DATE(2015, 5, 20)-5 - subtracts 5 days from May 20, 2015.
For additionally you can visit here.
... View more