<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Partial search head pooling in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84711#M3063</link>
    <description>&lt;P&gt;This is probably not a supported way of handling this but we hacked this behavior by shutting off the scheduler search processor for the interactive search head and pooling with another search head that was left as the "job server".  This job server would pick up and run scheduled searches while the interactive server could still be used to schedule searches.  Not a perfect solution and there are other issues like trying to change scheduled search run times from the interactive search head.&lt;/P&gt;

&lt;P&gt;See &lt;BR /&gt;
 .../etc/modules/internal/scheduler/config.xml&lt;/P&gt;</description>
    <pubDate>Thu, 30 Aug 2012 21:38:22 GMT</pubDate>
    <dc:creator>hdre</dc:creator>
    <dc:date>2012-08-30T21:38:22Z</dc:date>
    <item>
      <title>Partial search head pooling</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84707#M3059</link>
      <description>&lt;P&gt;I have a two search heads - but they perform different tasks.  One head is for running scheduled searches and the other is for interactive searches.  I'd like to utilize search head pooling - but I don't want to share any of the savedsearches.conf files.  Is this possible?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2011 19:52:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84707#M3059</guid>
      <dc:creator>nocostk</dc:creator>
      <dc:date>2011-04-19T19:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: Partial search head pooling</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84708#M3060</link>
      <description>&lt;P&gt;Search Head Pooling (SHP) is an all or nothing option at the moment. Once you enable it (splunk pooling enable &lt;PATH_TO_SHARED_STORAGE&gt;), it uses your SHP path for the "users" and "apps" folder.&lt;/PATH_TO_SHARED_STORAGE&gt;&lt;/P&gt;

&lt;P&gt;However, since your users will not be logging into the other Search Head (Job Server) there should be no saved searches on that server to push to the SHP.&lt;/P&gt;

&lt;P&gt;If you are using it for two distinctly different purposes, what reasons do you have for enabling SHP?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2011 21:29:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84708#M3060</guid>
      <dc:creator>msettipane</dc:creator>
      <dc:date>2011-04-19T21:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Partial search head pooling</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84709#M3061</link>
      <description>&lt;P&gt;I'd like to use SHP as a means of keeping my eventtypes.conf and tags.conf in sync.  Sometimes it's a bit tiresome to continually ask developers to create their tags/eventtypes in both locations.  If someone has any other ideas I'm all ears.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2011 12:28:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84709#M3061</guid>
      <dc:creator>nocostk</dc:creator>
      <dc:date>2011-04-20T12:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: Partial search head pooling</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84710#M3062</link>
      <description>&lt;P&gt;Are there any road blocks that keep you from setting up SHP? What is the reason for not wanting saved searches on both servers?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2011 14:00:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84710#M3062</guid>
      <dc:creator>msettipane</dc:creator>
      <dc:date>2011-04-20T14:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Partial search head pooling</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84711#M3063</link>
      <description>&lt;P&gt;This is probably not a supported way of handling this but we hacked this behavior by shutting off the scheduler search processor for the interactive search head and pooling with another search head that was left as the "job server".  This job server would pick up and run scheduled searches while the interactive server could still be used to schedule searches.  Not a perfect solution and there are other issues like trying to change scheduled search run times from the interactive search head.&lt;/P&gt;

&lt;P&gt;See &lt;BR /&gt;
 .../etc/modules/internal/scheduler/config.xml&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2012 21:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84711#M3063</guid>
      <dc:creator>hdre</dc:creator>
      <dc:date>2012-08-30T21:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Partial search head pooling</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84712#M3064</link>
      <description>&lt;P&gt;There is a better way to do this. See my answer.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2012 00:19:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84712#M3064</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-08-31T00:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: Partial search head pooling</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84713#M3065</link>
      <description>&lt;P&gt;You can't "partially" pool. however, you can disable the scheduler on the one that isn't supposed to run jobs. @hdre did this, but did this in a dangerous way. The right way to do this is to stick this in default-mode.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[pipeline:scheduler]
disabled_processors = LiveSplunks
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This does the same thing as hdre suggested, but more safely (e.g., it won't get overwritten on a patch or upgrade).&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2012 00:22:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Partial-search-head-pooling/m-p/84713#M3065</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-08-31T00:22:40Z</dc:date>
    </item>
  </channel>
</rss>

