<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search Head on Splunk Cloud in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Search-Head-on-Splunk-Cloud/m-p/204983#M23685</link>
    <description>&lt;P&gt;A base build is 1-3 (being one search head and 3x indexers). Of course, each build is sized to a customer's initial target ingest rate, data retention, etc.&lt;/P&gt;

&lt;P&gt;If a customer is large enough (enough concurrent users) a search head &lt;EM&gt;might&lt;/EM&gt; initially be deployed. Otherwise they are single search heads.&lt;/P&gt;

&lt;P&gt;You are correct, if there is a premium app purchased (such as ES or ITSI) that warrants it's own search head, then a second (or more) search head will be deployed. Typically a base search head is at a canonical name &lt;A href="https://.splunkcloud.com" target="test_blank"&gt;https://.splunkcloud.com&lt;/A&gt; where the additional ES search head would reside at &lt;A href="https://es-.splunkcloud.com"&gt;https://es-.splunkcloud.com&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;Again, that being said, if the size of the customer, concurrent users, search load, etc. - then a search head cluster might be deployed (for the ad-hoc searching purposes or independently for ES).&lt;/P&gt;

&lt;P&gt;As for propagation across search heads and indexers, it depends on the app. If the app requires indexing time props/transforms then there will be configuration pieces on the indexers. If the app only has search time props/transforms then it may only reside on the search head (or search heads if in a search head cluster).&lt;/P&gt;</description>
    <pubDate>Fri, 05 Aug 2016 20:51:15 GMT</pubDate>
    <dc:creator>pgreer_splunk</dc:creator>
    <dc:date>2016-08-05T20:51:15Z</dc:date>
    <item>
      <title>Search Head on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Search-Head-on-Splunk-Cloud/m-p/204981#M23683</link>
      <description>&lt;P&gt;Hi...I believe Splunk Cloud has 3 indexers, what about Search Heads?  If there multiple Search Heads, does the ES app get propagated across SH clusters &amp;amp; Index clusters?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 02:44:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Search-Head-on-Splunk-Cloud/m-p/204981#M23683</guid>
      <dc:creator>cpraz_ord</dc:creator>
      <dc:date>2016-08-04T02:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Search-Head-on-Splunk-Cloud/m-p/204982#M23684</link>
      <description>&lt;P&gt;Take a look at these posts&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/331435/search-head-clustering-enterprise-security-and-pci.html"&gt;https://answers.splunk.com/answers/331435/search-head-clustering-enterprise-security-and-pci.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/231809/how-to-deploy-the-splunk-app-for-enterprise-securi.html"&gt;https://answers.splunk.com/answers/231809/how-to-deploy-the-splunk-app-for-enterprise-securi.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 03:14:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Search-Head-on-Splunk-Cloud/m-p/204982#M23684</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-08-04T03:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Search-Head-on-Splunk-Cloud/m-p/204983#M23685</link>
      <description>&lt;P&gt;A base build is 1-3 (being one search head and 3x indexers). Of course, each build is sized to a customer's initial target ingest rate, data retention, etc.&lt;/P&gt;

&lt;P&gt;If a customer is large enough (enough concurrent users) a search head &lt;EM&gt;might&lt;/EM&gt; initially be deployed. Otherwise they are single search heads.&lt;/P&gt;

&lt;P&gt;You are correct, if there is a premium app purchased (such as ES or ITSI) that warrants it's own search head, then a second (or more) search head will be deployed. Typically a base search head is at a canonical name &lt;A href="https://.splunkcloud.com" target="test_blank"&gt;https://.splunkcloud.com&lt;/A&gt; where the additional ES search head would reside at &lt;A href="https://es-.splunkcloud.com"&gt;https://es-.splunkcloud.com&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;Again, that being said, if the size of the customer, concurrent users, search load, etc. - then a search head cluster might be deployed (for the ad-hoc searching purposes or independently for ES).&lt;/P&gt;

&lt;P&gt;As for propagation across search heads and indexers, it depends on the app. If the app requires indexing time props/transforms then there will be configuration pieces on the indexers. If the app only has search time props/transforms then it may only reside on the search head (or search heads if in a search head cluster).&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 20:51:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Search-Head-on-Splunk-Cloud/m-p/204983#M23685</guid>
      <dc:creator>pgreer_splunk</dc:creator>
      <dc:date>2016-08-05T20:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Search-Head-on-Splunk-Cloud/m-p/712214#M29199</link>
      <description>&lt;P&gt;I see an architecture online for Splunk Cloud. The Splunk Cloud has Search Tier[Search Head(core), Search Head(Enterprise Security)], Indexing Tier(I see 3 indexers picture), Management Tier[Cluster Manager].&lt;BR /&gt;&lt;BR /&gt;Is this a valid Splunk Cloud architecture? If at all there is a search head cluster, will it be mentioned here in the architecture diagram? I'm trying to figure out if there are multiple instances of Splunk Cloud, can I know if knowledge objects present in 1 instance can be seen in other instance as well.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 14:29:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Search-Head-on-Splunk-Cloud/m-p/712214#M29199</guid>
      <dc:creator>KKuser</dc:creator>
      <dc:date>2025-02-21T14:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Search-Head-on-Splunk-Cloud/m-p/712219#M29200</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276389"&gt;@KKuser&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;at first, don't attach a new question to a so old one (nine years ago!) even if on the same topic because it's difficoult to have an answer, it's always better to create a new question.&lt;/P&gt;&lt;P&gt;Anyway, if you need information about a validated Splunk architecture for an on premise or hybrid installation&amp;nbsp; see at &lt;A href="https://docs.splunk.com/Documentation/SVA/current/Architectures/About" target="_blank"&gt;https://docs.splunk.com/Documentation/SVA/current/Architectures/About&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Anyway, in Splunk Cloud you only see two machines: one Search Head for ES and one Search Head for the other apps.&lt;/P&gt;&lt;P&gt;You don't know if there's a Search Head Cluster, probably not also because you see only two machines and SH Cluster need three machines.&lt;/P&gt;&lt;P&gt;In addition you can upload apps and this operation isn't possible on SH Clusters.&lt;/P&gt;&lt;P&gt;In addition, the Indexer layer ss not visible for you even if you see three Indexers and you cannot see the Cluster Manager.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Surely there are many instance of Splunk Cloud in different AWS machines.&lt;/P&gt;&lt;P&gt;For more information see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SVA/current/Architectures/SCPExperience" target="_blank"&gt;https://docs.splunk.com/Documentation/SVA/current/Architectures/SCPExperience&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 14:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Search-Head-on-Splunk-Cloud/m-p/712219#M29200</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-02-21T14:58:11Z</dc:date>
    </item>
  </channel>
</rss>

