So the instructions for installing this add-on include the following pertaining to installing on a search head cluster:
Search Head Clusters Yes You can install this add-on on a search head cluster for all search-time functionality.
Before installing this add-on to a cluster, make the following changes to the add-on package:
1. Remove the eventgen.conf file and all files in the Samples folder.
2. Remove the inputs.conf file.
Why would I need to remove the inputs.conf file? How would I get data from the sql server without it? Do i remove it from the deployment package, then add it to each splunk search head?
↧