The search head we use searches events from test and prod indexer. In prod, we only need to capture the one from prod indexer. Can we filter events coming from specific splunk_server? or how to point a search head to only get data from prod indexer?
↧