<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to install multiple search heads in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-install-multiple-search-heads/m-p/29835#M6044</link>
    <description>&lt;P&gt;The steps are pretty much the same for your 2nd/3rd/4th search heads.  You will, however, want to make sure that you copy/replicate your config apps/bundles to the additional search head so they use the same field extractions, lookups and such.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Dec 2011 22:35:24 GMT</pubDate>
    <dc:creator>dwaddle</dc:creator>
    <dc:date>2011-12-06T22:35:24Z</dc:date>
    <item>
      <title>How to install multiple search heads</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-install-multiple-search-heads/m-p/29832#M6041</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;

&lt;P&gt;I have a distributed splunk environment where I have 1 search head and 3 indexers.&lt;BR /&gt;
I would like to install second search head for maintenance reasons, so when I need to do kernel or splunk updates on first search head, second search head is still available for users.&lt;/P&gt;

&lt;P&gt;How can I accomplish this. ? Any links to an how to would be great too.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2011 22:10:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-install-multiple-search-heads/m-p/29832#M6041</guid>
      <dc:creator>mehmettecer</dc:creator>
      <dc:date>2011-12-06T22:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to install multiple search heads</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-install-multiple-search-heads/m-p/29833#M6042</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.2/Deploy/Installadedicatedsearchhead"&gt;http://docs.splunk.com/Documentation/Splunk/4.2/Deploy/Installadedicatedsearchhead&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2011 22:18:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-install-multiple-search-heads/m-p/29833#M6042</guid>
      <dc:creator>RicoSuave</dc:creator>
      <dc:date>2011-12-06T22:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to install multiple search heads</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-install-multiple-search-heads/m-p/29834#M6043</link>
      <description>&lt;P&gt;Thanks for the link. I already saw this one.&lt;/P&gt;

&lt;P&gt;I need to install my 2nd search head.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2011 22:22:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-install-multiple-search-heads/m-p/29834#M6043</guid>
      <dc:creator>mehmettecer</dc:creator>
      <dc:date>2011-12-06T22:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to install multiple search heads</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-install-multiple-search-heads/m-p/29835#M6044</link>
      <description>&lt;P&gt;The steps are pretty much the same for your 2nd/3rd/4th search heads.  You will, however, want to make sure that you copy/replicate your config apps/bundles to the additional search head so they use the same field extractions, lookups and such.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2011 22:35:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-install-multiple-search-heads/m-p/29835#M6044</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2011-12-06T22:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to install multiple search heads</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-install-multiple-search-heads/m-p/29836#M6045</link>
      <description>&lt;P&gt;Are you planning to use Search Head Pooling, optionally with both heads behind a load balancer so your users can transparently be failed over to another head (during maintenance) ?&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuresearchheadpooling"&gt;This link&lt;/A&gt; has some good info.&lt;/P&gt;

&lt;P&gt;A few key points :&lt;/P&gt;

&lt;P&gt;-you'll need shared storage(ie: NAS) so the search heads can share the same etc/apps , etc/users directorys&lt;/P&gt;

&lt;P&gt;-each head maintains its own etc/system directory&lt;/P&gt;

&lt;P&gt;-enable pooling on each head (simple to do using the CLI)&lt;/P&gt;

&lt;P&gt;-if using local users, the etc/passwd file  must be maintained on each search head.I prefer using LDAP authentication.&lt;/P&gt;

&lt;P&gt;-if using a load balancer and alerting , setup the load balancer host name as the alert link hostname.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2011 23:37:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-install-multiple-search-heads/m-p/29836#M6045</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2011-12-06T23:37:43Z</dc:date>
    </item>
  </channel>
</rss>

