Hi all,
Currently, our splunk dev environment consists of a standalone instance that is both our indexer and search head. What I am trying to do is set up a new search head that will connect to our production environment indexer, essentially mimicking production in development. I have a brand new instance that I just got set up that will act as a standalone search head. From here, would I add the indexer as a search peer in distributed search? I'm only about a week into learning splunk, so this stuff definitely confuses me a bit which is why I decided to ask on here.
Please let me know what you guys think is the best solution here.
↧