The topics we've covered so far include activities you'll perform on a fairly regular basis in your Splunk environment. We covered installing and configuring universal and heavy forwarders, and how to configure Splunk to input data from forwarders and other sources, including how to use the increasingly popular HTTP Event Collector. We then reviewed how to manage forwarders with the deployment server, got an introduction to Splunk apps, and learned how to create indexes, custom sourcetypes, and how to deploy those configurations to the indexing peers using the cluster master.
Now that we've got data flowing into our indexers, let's learn about a few other admin tasks in the next chapter!