<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Upgrade Requirement Clarification in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade-Requirement-Clarification/m-p/625873#M14977</link>
    <description>&lt;P&gt;What you describe sounds like a non-standard installation.&amp;nbsp; If the indexers are replicating buckets to each other then that would be an indexer cluster, which should not also be operating as search heads.&amp;nbsp; With an indexer cluster, the search heads should be separate instances.&lt;/P&gt;&lt;P&gt;To answer your question, yes, I believe all of your saved searches present on the indexers would violate the condition.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jan 2023 17:52:10 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-01-04T17:52:10Z</dc:date>
    <item>
      <title>Splunk Upgrade Requirement Clarification</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade-Requirement-Clarification/m-p/625760#M14964</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're preparing to upgrade SE from 8 to 9 and have a question about this requirement:&lt;/P&gt;&lt;P&gt;For distributed deployments of any kind, confirm that all machines in the indexing tier satisfy the following conditions:&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;...&lt;/LI&gt;&lt;LI&gt;...&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#000000"&gt;They do not run their own saved searches&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;If our indexers are also search heads, would that violate this?&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 22:15:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade-Requirement-Clarification/m-p/625760#M14964</guid>
      <dc:creator>R15</dc:creator>
      <dc:date>2023-01-03T22:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Upgrade Requirement Clarification</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade-Requirement-Clarification/m-p/625821#M14975</link>
      <description>&lt;P&gt;Indexers should not also be search heads, unless you have a collection of standalone Splunk instances (which would be uncommon).&lt;/P&gt;&lt;P&gt;A standalone instance is not a distributed deployment so the listed conditions do not apply.&lt;/P&gt;&lt;P&gt;In a distributed deployment, search head and indexer instances are on separate machines and the SHs send search requests to the indexers for fulfillment.&amp;nbsp; If this is the case at your company and you also have the indexers acting as search heads then you must make sure the indexers do not have their own saved searches.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 14:33:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade-Requirement-Clarification/m-p/625821#M14975</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-04T14:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Upgrade Requirement Clarification</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade-Requirement-Clarification/m-p/625868#M14976</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I'm new here and still trying to wrap my around this as I prepare to help upgrade and then later expand our setup. It's a very small deployment (for now), 2 indexers which are also search heads with replication between indexers. Would this mean ALL of our saved searches violate the above?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 16:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade-Requirement-Clarification/m-p/625868#M14976</guid>
      <dc:creator>R15</dc:creator>
      <dc:date>2023-01-04T16:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Upgrade Requirement Clarification</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade-Requirement-Clarification/m-p/625873#M14977</link>
      <description>&lt;P&gt;What you describe sounds like a non-standard installation.&amp;nbsp; If the indexers are replicating buckets to each other then that would be an indexer cluster, which should not also be operating as search heads.&amp;nbsp; With an indexer cluster, the search heads should be separate instances.&lt;/P&gt;&lt;P&gt;To answer your question, yes, I believe all of your saved searches present on the indexers would violate the condition.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 17:52:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade-Requirement-Clarification/m-p/625873#M14977</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-04T17:52:10Z</dc:date>
    </item>
  </channel>
</rss>

