My current splunk setup is a pre-processing system forwarding to one system. That system is a search head and indexer. I offloaded some processing to the heavy forwarder. However, as the data grew, the search became slower and storage lowered.
I need some advice.
I have secured some funds to get 2 new systems. I intend to re-setup my Splunk server to the following configuration. 1 pre-proc, 2 indexers and 1 search head (current indexer+search head). However, I do not know how to move the indexes to the other system and continue to let the system perform as usual.
... View more