<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk install as 2 tier architecture in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Splunk-install-as-2-tier-architecture/m-p/333366#M8933</link>
    <description>&lt;P&gt;Not only is a two-tier architecture possible, it's recommended for all but the smallest installations.  See &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/Deploy/Distributedoverview"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.2/Deploy/Distributedoverview&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Mar 2017 12:50:05 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2017-03-02T12:50:05Z</dc:date>
    <item>
      <title>Splunk install as 2 tier architecture</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-install-as-2-tier-architecture/m-p/333365#M8932</link>
      <description>&lt;P&gt;I would like to know is it possible to install splunk in two tier architecture. One server shoudl store all the logs (probably indexer), the other one should just search through these logs and display them to the client (search head). Is there any instruction how to install splunk in such architecture? One important factor: logs cannot be stored persistently in any way on presentation server - this is our security requirements.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 09:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-install-as-2-tier-architecture/m-p/333365#M8932</guid>
      <dc:creator>przemyslawpiest</dc:creator>
      <dc:date>2017-03-02T09:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk install as 2 tier architecture</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-install-as-2-tier-architecture/m-p/333366#M8933</link>
      <description>&lt;P&gt;Not only is a two-tier architecture possible, it's recommended for all but the smallest installations.  See &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/Deploy/Distributedoverview"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.2/Deploy/Distributedoverview&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 12:50:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-install-as-2-tier-architecture/m-p/333366#M8933</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-03-02T12:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk install as 2 tier architecture</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-install-as-2-tier-architecture/m-p/333367#M8934</link>
      <description>&lt;P&gt;If I understand right we need than 2 heavy forwarders installed and properly configure them sa one will be an indexer, the other search head. Am i right? Is there any documentation on how to configure this in such way?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 12:57:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-install-as-2-tier-architecture/m-p/333367#M8934</guid>
      <dc:creator>przemyslawpiest</dc:creator>
      <dc:date>2017-03-02T12:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk install as 2 tier architecture</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-install-as-2-tier-architecture/m-p/333368#M8935</link>
      <description>&lt;P&gt;You don't need any heavy forwarders.  Install 2 separate instances of Splunk Enterprise.  One will be the search head (SH) and license master; the other will be the indexer.  Configure the indexer as a license slave pointing to the SH.  On the SH, configure distributed search using the indexer as a search peer.&lt;/P&gt;

&lt;P&gt;Relevant documentation is a bit scattered, but start with the Distributed Search manual at &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/DistSearch/Whatisdistributedsearch"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.2/DistSearch/Whatisdistributedsearch&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 13:45:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-install-as-2-tier-architecture/m-p/333368#M8935</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-03-02T13:45:40Z</dc:date>
    </item>
  </channel>
</rss>

