Please correct my simple step by step in linux environment:
Forwarder :
-Install splunkforwarder, accept license, enable boot-start.
-/opt/splunkforwarder/bin/splunk add forward-server ip-myindexer-server:9997
-/opt/splunkforwarder/bin/splunk list forward-server
-/opt/splunkforwarder/bin/splunk add monitor /var/log/apache/logs/ -index main -sourcetype %app%
Indexer :
-install splunk enterprise, accept license, enable boot-start.
-/opt/splunk/bin/splunk enable listen 9997
Search Head :
I dont know how to add indexer using CLI ?
Deployment Server :
I dont know how to setup here ?
All this is covered in the docs - read more here: http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Implementadistributeddeployment
http://docs.splunk.com/Documentation/Splunk/6.0.2/DistSearch/Whatisdistributedsearch
http://docs.splunk.com/Documentation/Splunk/6.0.2/Updating/Aboutdeploymentserver