So far I have an Fowarder feeding data into my Indexer where I have a search head setup to search the indexes. If i wanted to set up a Deployment Manager to look after my indexer and search head how would i go about configuring this setup?? Im so lost and confused right now.
It is straightforward. You just need to provide your "Splunk forwarder" file:
${SPLUNK_FWD_HOME}/etc/apps/deployclient/local/deploymentclient.conf
with below entry
[deployment-client]
[target-broker:deploymentServer]
targetUri = <DEPLOY_SERVER>
I've automated installation of Splunk Forwarder in Windows/Linux. Code can be found here