I have two servers in my Splunk Deployment:
1 Indexer
1 Everything else (not indexer)
I installed Splunk DB Connect on my Search head, however, when I was trying to configure the DB Inputs, I was not able to select the index I wanted to send the data to.
Documentation suggests that it should be installed on the search head, however, I am not sure how to get the data into the correct index on the indexer.
↧