<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic knowledge bundle without a shared storage? in Security</title>
    <link>https://community.splunk.com/t5/Security/knowledge-bundle-without-a-shared-storage/m-p/41419#M13797</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have one search head and one indexer. How can I use the Knowledge bundle without using a shared storage?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Maryam&lt;/P&gt;</description>
    <pubDate>Tue, 21 May 2013 16:50:52 GMT</pubDate>
    <dc:creator>MarMoh</dc:creator>
    <dc:date>2013-05-21T16:50:52Z</dc:date>
    <item>
      <title>knowledge bundle without a shared storage?</title>
      <link>https://community.splunk.com/t5/Security/knowledge-bundle-without-a-shared-storage/m-p/41419#M13797</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have one search head and one indexer. How can I use the Knowledge bundle without using a shared storage?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Maryam&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2013 16:50:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/knowledge-bundle-without-a-shared-storage/m-p/41419#M13797</guid>
      <dc:creator>MarMoh</dc:creator>
      <dc:date>2013-05-21T16:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: knowledge bundle without a shared storage?</title>
      <link>https://community.splunk.com/t5/Security/knowledge-bundle-without-a-shared-storage/m-p/41420#M13798</link>
      <description>&lt;P&gt;I am curious as to what has you thinking you need/want to do this? This is designed mostly for multiple indexers. True it is a performance consideration but with your configuration I don't know that it will gain you much improvments.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2013 19:36:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/knowledge-bundle-without-a-shared-storage/m-p/41420#M13798</guid>
      <dc:creator>rgcurry</dc:creator>
      <dc:date>2013-05-21T19:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: knowledge bundle without a shared storage?</title>
      <link>https://community.splunk.com/t5/Security/knowledge-bundle-without-a-shared-storage/m-p/41421#M13799</link>
      <description>&lt;P&gt;Well, Just doing it for the future scalability purposes.So for one search head and one indexer I do not need to use the bundle? &lt;BR /&gt;
another question is in future if I add more indexers how much work it would be to configure the Knowledge Bundle?&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2013 19:40:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/knowledge-bundle-without-a-shared-storage/m-p/41421#M13799</guid>
      <dc:creator>MarMoh</dc:creator>
      <dc:date>2013-05-21T19:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: knowledge bundle without a shared storage?</title>
      <link>https://community.splunk.com/t5/Security/knowledge-bundle-without-a-shared-storage/m-p/41422#M13800</link>
      <description>&lt;P&gt;If I don't misunderstand you somehow what you're asking for is really the normal way to setup distributed search. Configure the indexer as a search peer to the search head, and the search head will automatically send the knowledge bundles the indexer needs when issuing searches. &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Configuredistributedsearch"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Configuredistributedsearch&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2013 20:58:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/knowledge-bundle-without-a-shared-storage/m-p/41422#M13800</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-05-21T20:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: knowledge bundle without a shared storage?</title>
      <link>https://community.splunk.com/t5/Security/knowledge-bundle-without-a-shared-storage/m-p/41423#M13801</link>
      <description>&lt;P&gt;As Ayn said above, the Knowledge Bundle is a part of normal processing. It seems to me that you are considering Search Head pooling where the information the Search Heads send to the Indexers is made static and stored on a shared file system to which all Search Heads and Indexers can access and updated when there are changes made to these configs. More info at &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Configuresearchheadpooling"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Configuresearchheadpooling&lt;/A&gt;. Know that there is a performance hit with this option; your milage may vary.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2013 13:54:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/knowledge-bundle-without-a-shared-storage/m-p/41423#M13801</guid>
      <dc:creator>rgcurry</dc:creator>
      <dc:date>2013-05-29T13:54:30Z</dc:date>
    </item>
  </channel>
</rss>

