<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding a Search Head? Help in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Adding-a-Search-Head-Help/m-p/33272#M940</link>
    <description>&lt;P&gt;Yes, a SH is a good candidate to run in a VM.  And it never hurts to build out a distributed environment to handle current needs and future growth. Reference from a previous answer &lt;A href="http://splunk-base.splunk.com/answers/298/can-i-run-splunk-in-a-vm-are-there-any-issues-or-tricks-i-should-be-aware-of"&gt;here&lt;/A&gt;.  Typically you wouldn't move to a stand alone search head until you had at least two indexers though.   I would recommend talking to a Splunk sales team that can put you in touch with our Professional services folks who could implement this for you and show you how to scale it in the future.&lt;/P&gt;

&lt;P&gt;Adding another search head in the future is very straight forward since Splunk has a flexible architecture. The same applies to indexers as well. (&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Configuredistributedsearch"&gt;doc link&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;Search head pooling may be beneficial depending on your requirements.  It certainly allows you to share the configurations and avoid replicating data across your indexers for each new search. &lt;/P&gt;

&lt;P&gt;You will most likely want to front end multiple search heads with a load balancer and then you can send all users to one place and SH pooling takes care of having all users see what is expected.&lt;/P&gt;</description>
    <pubDate>Tue, 14 May 2013 18:12:41 GMT</pubDate>
    <dc:creator>sdaniels</dc:creator>
    <dc:date>2013-05-14T18:12:41Z</dc:date>
    <item>
      <title>Adding a Search Head? Help</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Adding-a-Search-Head-Help/m-p/33271#M939</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;Currently I have a standalone splunk (Enterprise). Since the data volume is growing so fast we decided to add a VM as a dedicated Search Head and use the existing one as an indexer, but I have too many questions in order to proceed:&lt;BR /&gt;
1-is it even a good idea to use VM as a dedicated search head?&lt;BR /&gt;
2-in the documents here(&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Summaryofperformancerecommendations"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Summaryofperformancerecommendations&lt;/A&gt;) number of search users are too low. Data volume wise 1 head would be enough for us but number of search users is only 4! right now too many people are using the current Splunk at the same time! &lt;BR /&gt;
3-how much work does it take to add another search head in future? Should I make a pool? How is it going to impact the end users when we are doing it?&lt;BR /&gt;
4-How end users can access the Splunk if we have multiple search heads or indexers. Right now we just access through &lt;A href="https://splunk"&gt;https://splunk&lt;/A&gt;. &lt;BR /&gt;
We are so concerned about scalability and the possible impact if we need to change the configuration in future. We'd rather configure 2 search heads now rather than next year if it impacts our end users!&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
M&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2013 16:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Adding-a-Search-Head-Help/m-p/33271#M939</guid>
      <dc:creator>MarMoh</dc:creator>
      <dc:date>2013-05-14T16:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a Search Head? Help</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Adding-a-Search-Head-Help/m-p/33272#M940</link>
      <description>&lt;P&gt;Yes, a SH is a good candidate to run in a VM.  And it never hurts to build out a distributed environment to handle current needs and future growth. Reference from a previous answer &lt;A href="http://splunk-base.splunk.com/answers/298/can-i-run-splunk-in-a-vm-are-there-any-issues-or-tricks-i-should-be-aware-of"&gt;here&lt;/A&gt;.  Typically you wouldn't move to a stand alone search head until you had at least two indexers though.   I would recommend talking to a Splunk sales team that can put you in touch with our Professional services folks who could implement this for you and show you how to scale it in the future.&lt;/P&gt;

&lt;P&gt;Adding another search head in the future is very straight forward since Splunk has a flexible architecture. The same applies to indexers as well. (&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Configuredistributedsearch"&gt;doc link&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;Search head pooling may be beneficial depending on your requirements.  It certainly allows you to share the configurations and avoid replicating data across your indexers for each new search. &lt;/P&gt;

&lt;P&gt;You will most likely want to front end multiple search heads with a load balancer and then you can send all users to one place and SH pooling takes care of having all users see what is expected.&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2013 18:12:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Adding-a-Search-Head-Help/m-p/33272#M940</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2013-05-14T18:12:41Z</dc:date>
    </item>
  </channel>
</rss>

