<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add Enterprise Security to on prem clustered environment in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674672#M18407</link>
    <description>&lt;P&gt;Thanks a lot&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;. Answer to Question 2 is exactly what I supposed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding point 1, is the syntax I posted is the one to use to "insert" ES on environment or should I use another one?&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jan 2024 14:15:43 GMT</pubDate>
    <dc:creator>SplunkExplorer</dc:creator>
    <dc:date>2024-01-18T14:15:43Z</dc:date>
    <item>
      <title>Add Enterprise Security to on prem clustered environment</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674660#M18405</link>
      <description>&lt;P&gt;Hi Splunkers, I have a doubt about setting for Splunk Enterprise Security.&lt;/P&gt;&lt;P&gt;As usual when I put a question here, let me share a minimal of context and assumption.&lt;/P&gt;&lt;P&gt;Environment:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A completely on prem Splunk Enterprise (no Slunk Cloud SaaS).&lt;/LI&gt;&lt;LI&gt;Currently, only one SH&lt;/LI&gt;&lt;LI&gt;Clustered indexers&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Task:&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Install and configure a SH with Splunk Enterprise Security.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Assumption:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I know the full installation procedure (doc + Splunk Enterprise Admin course)&lt;/LI&gt;&lt;LI&gt;I know how to manage a cluster environment (doc + Architect course). For example, I know that if I have to set a Splunk instance as SH I can use, from CLI:&lt;/LI&gt;&lt;/UL&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; splunk edit cluster-config
-mode searchhead
-manager_uri https://&amp;lt;manager node address&amp;gt;
-secret &amp;lt;cluster secret&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;This syntax is still valid to add a SH with ES installed on it? The doubt is if the ES presence should lead me to use a different approach to tell "Hey, SH wth ES: indexers to query are those".&lt;/LI&gt;&lt;LI&gt;SH with ES component should be&amp;nbsp; add as single SH (so, decoupled from already existing SH) or should I create a SH Cluster with normal SH + ES ES?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 18 Jan 2024 13:50:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674660#M18405</guid>
      <dc:creator>SplunkExplorer</dc:creator>
      <dc:date>2024-01-18T13:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: Add Enterprise Security to on prem clustered environment</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674667#M18406</link>
      <description>&lt;P&gt;The ES SH should be kept separate and not joined with the existing SH into a cluster because: 1) you need at least 3 SHs to make a cluster; 2) SHs must be virgin to form a cluster; 3) ES doesn't play well with other apps and so needs to be on its own.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 14:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674667#M18406</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-01-18T14:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Add Enterprise Security to on prem clustered environment</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674672#M18407</link>
      <description>&lt;P&gt;Thanks a lot&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;. Answer to Question 2 is exactly what I supposed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding point 1, is the syntax I posted is the one to use to "insert" ES on environment or should I use another one?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 14:15:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674672#M18407</guid>
      <dc:creator>SplunkExplorer</dc:creator>
      <dc:date>2024-01-18T14:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Add Enterprise Security to on prem clustered environment</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674675#M18408</link>
      <description>&lt;P&gt;You install ES differently on a standalone SH and on a SHC. So you must either firstly set up a SHC (and for that you don't use an existing SH - you spin up a clear SH and join it to the SHC). Whether you want a SHC depends on your needs and expected workload. You can create a SHC (but again - you must create a new SHC and then possibly migrate some of your settings from existing standalone SH manually) and install ES on it. But just as well you could set up a dedicated SH just for ES use (and use the other SH for "normal" Splunk work). Both approaches have their pros and cons. Single SHC is bigger in minimal option (you need at least three SHs for the SHC and a deployer) but is probably easier to manage than two separate SHs - they can be painful to keep relevant configs in sync.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 14:27:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674675#M18408</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-18T14:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Add Enterprise Security to on prem clustered environment</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674684#M18409</link>
      <description>&lt;P&gt;The syntax you gave is the right one for adding a new SH to a cluster, but you don't need it just to install ES on an SH.&amp;nbsp; Create a new SH and install ES on it using the instructions in the ES manual.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 15:01:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674684#M18409</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-01-18T15:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Add Enterprise Security to on prem clustered environment</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674862#M18415</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249714"&gt;@SplunkExplorer&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi Splunkers, I have a doubt about setting for Splunk Enterprise Security.&lt;/P&gt;&lt;P&gt;As usual when I put a question here, let me share a minimal of context and assumption.&lt;/P&gt;&lt;P&gt;Environment:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A completely on prem Splunk Enterprise (no Slunk Cloud SaaS).&lt;/LI&gt;&lt;LI&gt;Currently, only one SH&lt;/LI&gt;&lt;LI&gt;Clustered indexers&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Task:&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Install and configure a SH with Splunk Enterprise Security.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Assumption:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I know the full installation procedure (doc + Splunk Enterprise Admin course)&lt;/LI&gt;&lt;LI&gt;I know how to manage a cluster environment (doc + Architect course). For example, I know that if I have to set a Splunk instance as SH I can use, from CLI:&lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; splunk edit cluster-config
-mode searchhead
-manager_uri https://&amp;lt;manager node address&amp;gt;
-secret &amp;lt;cluster secret&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;This syntax is still valid to add a SH with ES installed on it? The doubt is if the ES presence should lead me to use a different approach to tell "Hey, SH wth ES: indexers to query are those".&lt;/LI&gt;&lt;LI&gt;SH with ES component should be&amp;nbsp; add as single SH (so, decoupled from already existing SH) or should I create a SH Cluster with normal SH + ES ES?&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249714"&gt;@SplunkExplorer&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi Splunkers, I have a doubt about setting for Splunk Enterprise Security.&lt;/P&gt;&lt;P&gt;As usual when I put a question here, let me share a minimal of context and assumption.&lt;/P&gt;&lt;P&gt;Environment:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A completely on prem Splunk Enterprise (no Slunk Cloud SaaS).&lt;/LI&gt;&lt;LI&gt;Currently, only one SH&lt;/LI&gt;&lt;LI&gt;Clustered indexers&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Task:&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Install and configure a SH with Splunk Enterprise Security.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Assumption:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I know the full installation procedure (doc + Splunk Enterprise Admin course)&lt;/LI&gt;&lt;LI&gt;I know how to manage a cluster environment (doc + Architect course). For example, I know that if I have to set a Splunk instance as SH I can use, from CLI:&lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; splunk edit cluster-config
-mode searchhead
-manager_uri https://&amp;lt;manager node address&amp;gt;
-secret &amp;lt;cluster secret&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;This syntax is still valid to add a SH with ES installed on it? The doubt is if the ES presence should lead me to use a different approach to tell "Hey, SH wth ES: indexers to query are those".&lt;/LI&gt;&lt;LI&gt;SH with ES component should be&amp;nbsp; add as single SH (so, decoupled from already existing SH) or should I create a SH Cluster with normal SH + ES ES?&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;P&gt;Check DM.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 17:39:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Add-Enterprise-Security-to-on-prem-clustered-environment/m-p/674862#M18415</guid>
      <dc:creator>SplunkExplorer_</dc:creator>
      <dc:date>2024-01-19T17:39:03Z</dc:date>
    </item>
  </channel>
</rss>

