Splunk 7.x Quick Start Guide
上QQ阅读APP看书,第一时间看更新

Configuring Splunk components

If you have installed Splunk Enterprise on all of the servers you've planned for in your deployment, you're now ready to perform the changes needed to a few key files that will configure each component to perform its specific function—search head, indexer, and so on.

Before we get started with that, though, it would be a good idea to do a quick review of where Splunk keeps the files you'll be working with the most, and touch on something called 'precedence,' which is important for understanding how the configuration files work together in a complex system.