When running a real-time search, search results are pulled from which Splunk component?
Which parent directory contains the configuration files in Splunk?
How would you configure your distsearch conf to allow you to run the search below?
sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON
The CLI command splunk add forward-server indexer:<receiving-port> will create stanza(s) in which configuration file?
When running a real-time search, search results are pulled from which Splunk component?