<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to set up a Splunk deployment with just 1 indexer and 1 search head? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260429#M49994</link>
    <description>&lt;P&gt;Anyone have any experience in this? I'm insure of how to set it up as DMC gives me that warning &lt;/P&gt;

&lt;P&gt;I imagine there probably a way to do it all through command line if DMC doesn't support . Any direction or walk through / how to's to on how to make this happen is appreciated. &lt;/P&gt;</description>
    <pubDate>Sat, 16 Jul 2016 03:13:37 GMT</pubDate>
    <dc:creator>Jarohnimo</dc:creator>
    <dc:date>2016-07-16T03:13:37Z</dc:date>
    <item>
      <title>Is it possible to set up a Splunk deployment with just 1 indexer and 1 search head?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260427#M49992</link>
      <description>&lt;P&gt;Is it possible to set up Splunk with Just 1 Indexer, and 1 Search head? I began to attempt this through the Distributed Management Console, but received a nasty warning about not setting up DMC on a box that would be a SH as it would not be supported by Splunk. Is DMC not the way to go for this?&lt;/P&gt;

&lt;P&gt;Is it possible to have a setup with only 2 servers (1 sh, 1 indexer)? If so, can someone please provide clear instruction on how to do so as this wasn't clear in the Splunk documentation I've read.&lt;/P&gt;

&lt;P&gt;Respectfully,&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 22:12:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260427#M49992</guid>
      <dc:creator>Jarohnimo</dc:creator>
      <dc:date>2016-07-14T22:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to set up a Splunk deployment with just 1 indexer and 1 search head?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260428#M49993</link>
      <description>&lt;P&gt;The &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.1/Deploy/Searchheadwithindexers"&gt;Small enterprise deployment: Single search head with multiple indexers&lt;/A&gt; describes a close enough scenario.&lt;/P&gt;

&lt;P&gt;It shows -&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1585iCC17254BE874A059/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;In one of the original courses, they show a transition from one Splunk server to the original one as the Indexer and a new one as a SH. So, what you are trying to do is legitimate ; -)&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 00:32:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260428#M49993</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-07-15T00:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to set up a Splunk deployment with just 1 indexer and 1 search head?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260429#M49994</link>
      <description>&lt;P&gt;Anyone have any experience in this? I'm insure of how to set it up as DMC gives me that warning &lt;/P&gt;

&lt;P&gt;I imagine there probably a way to do it all through command line if DMC doesn't support . Any direction or walk through / how to's to on how to make this happen is appreciated. &lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2016 03:13:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260429#M49994</guid>
      <dc:creator>Jarohnimo</dc:creator>
      <dc:date>2016-07-16T03:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to set up a Splunk deployment with just 1 indexer and 1 search head?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260430#M49995</link>
      <description>&lt;P&gt;Works just fine, just make sure you have the spare capacity to run a few scheduled things from the DMC.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2016 08:31:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260430#M49995</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-07-16T08:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to set up a Splunk deployment with just 1 indexer and 1 search head?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260431#M49996</link>
      <description>&lt;P&gt;Can some one provide a how to guide link? I'm unable to find actual instructions on how to set this up. I find lots of articles that tal about the concept and the technology but nothing as granular as.&lt;BR /&gt;
Cd to bin and type splunk add indexer ..... &amp;lt;--- does something like this exist ? If so is it possible to setup via DMC?&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2016 22:51:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260431#M49996</guid>
      <dc:creator>Jarohnimo</dc:creator>
      <dc:date>2016-07-16T22:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to set up a Splunk deployment with just 1 indexer and 1 search head?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260432#M49997</link>
      <description>&lt;P&gt;Here's all you need to know about adding a search peer (indexer) to a search head: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/DistSearch/Configuredistributedsearch"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/DistSearch/Configuredistributedsearch&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2016 22:57:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260432#M49997</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-07-16T22:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to set up a Splunk deployment with just 1 indexer and 1 search head?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260433#M49998</link>
      <description>&lt;P&gt;Thank you, I'd like to vote yours as the correct answer but i'm unsure how to do so. It's only allowing me to accept the first person's response as the answer.. smh &lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2016 23:05:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260433#M49998</guid>
      <dc:creator>Jarohnimo</dc:creator>
      <dc:date>2016-07-16T23:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to set up a Splunk deployment with just 1 indexer and 1 search head?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260434#M49999</link>
      <description>&lt;P&gt;I have converted the comment, so if this answers your question you can accept it as such.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 20:49:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260434#M49999</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-07-25T20:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to set up a Splunk deployment with just 1 indexer and 1 search head?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260435#M50000</link>
      <description>&lt;P&gt;I downvoted this post because not the best answer&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2016 01:09:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-set-up-a-Splunk-deployment-with-just-1-indexer/m-p/260435#M50000</guid>
      <dc:creator>Jarohnimo</dc:creator>
      <dc:date>2016-07-26T01:09:42Z</dc:date>
    </item>
  </channel>
</rss>

