<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: convert a stand-alone splunk instance to a dedicated indexer? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/convert-a-stand-alone-splunk-instance-to-a-dedicated-indexer/m-p/38056#M6977</link>
    <description>&lt;P&gt;You should read this whole section of the docs carefully:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Whatisdistributedsearch#What_search_heads_send_to_search_peers"&gt;About distributed search&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The basic process is:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Install a dedicated search head.&lt;/LI&gt;
&lt;LI&gt;copy any apps you have to the new search head.  Remove any inputs that you have so you are not receiving or indexing on the new search head.&lt;/LI&gt;
&lt;LI&gt;enable distributed search on the search head.&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Add the old indexer as a search peer on the search head.&lt;/LI&gt;
&lt;LI&gt;search for something and look to see if you see the indexer in the splunk_server field&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;After that, it is up to you if you want to disable the web ui on the old indexer.  It is also up to you if you want to organize your apps better so only the correct pieces are on the search head.  This isn't strictly necessary because splunk will ignore settings that do not apply to the type of server but it is a best practice.&lt;/P&gt;

&lt;P&gt;I would read this to help you understand how configurations work in a distributed deployment:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F"&gt;Where do I configure my splunk settings&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 17 May 2013 13:27:22 GMT</pubDate>
    <dc:creator>okrabbe_splunk</dc:creator>
    <dc:date>2013-05-17T13:27:22Z</dc:date>
    <item>
      <title>convert a stand-alone splunk instance to a dedicated indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/convert-a-stand-alone-splunk-instance-to-a-dedicated-indexer/m-p/38055#M6976</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;Currently there is just one stand alone splunk server running for the entire company, we decided to change the architecture and add a search head and use the existing server as a dedicated indexer. I want to know:&lt;BR /&gt;
1.How can I do that (get the search component off of the existing server and make it a dedicated indexer)?&lt;BR /&gt;
2.How to migrate the search configuration from the existing Splunk to the search head?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
M&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2013 13:18:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/convert-a-stand-alone-splunk-instance-to-a-dedicated-indexer/m-p/38055#M6976</guid>
      <dc:creator>MarMoh</dc:creator>
      <dc:date>2013-05-17T13:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: convert a stand-alone splunk instance to a dedicated indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/convert-a-stand-alone-splunk-instance-to-a-dedicated-indexer/m-p/38056#M6977</link>
      <description>&lt;P&gt;You should read this whole section of the docs carefully:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Whatisdistributedsearch#What_search_heads_send_to_search_peers"&gt;About distributed search&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The basic process is:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Install a dedicated search head.&lt;/LI&gt;
&lt;LI&gt;copy any apps you have to the new search head.  Remove any inputs that you have so you are not receiving or indexing on the new search head.&lt;/LI&gt;
&lt;LI&gt;enable distributed search on the search head.&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Add the old indexer as a search peer on the search head.&lt;/LI&gt;
&lt;LI&gt;search for something and look to see if you see the indexer in the splunk_server field&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;After that, it is up to you if you want to disable the web ui on the old indexer.  It is also up to you if you want to organize your apps better so only the correct pieces are on the search head.  This isn't strictly necessary because splunk will ignore settings that do not apply to the type of server but it is a best practice.&lt;/P&gt;

&lt;P&gt;I would read this to help you understand how configurations work in a distributed deployment:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F"&gt;Where do I configure my splunk settings&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2013 13:27:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/convert-a-stand-alone-splunk-instance-to-a-dedicated-indexer/m-p/38056#M6977</guid>
      <dc:creator>okrabbe_splunk</dc:creator>
      <dc:date>2013-05-17T13:27:22Z</dc:date>
    </item>
  </channel>
</rss>

