<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Real-time alerting with search head pooling in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Real-time-alerting-with-search-head-pooling/m-p/36607#M8130</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have a distributed environment with 2 search heads in a pool (for LB and HA) running v4.3.0 (upgrading shortly). &lt;BR /&gt;
When scheduling real-time searches, both search heads start processing the events simultaneously (There is splunkd search processes running on each search head).&lt;BR /&gt;
Then when an alert if fired, both search heads trigger the alert (for example, both search heads send an email; even with throttling enabled).&lt;/P&gt;

&lt;P&gt;1.Is it correct that both search heads run the scheduled real-time search? What is the benefit of this, as is just seems to put undue load on the environment?&lt;/P&gt;

&lt;P&gt;2.Is it possible to restrict this real-time searching to only occur on one or the two search heads?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Mark&lt;/P&gt;</description>
    <pubDate>Thu, 16 Aug 2012 04:48:57 GMT</pubDate>
    <dc:creator>mark</dc:creator>
    <dc:date>2012-08-16T04:48:57Z</dc:date>
    <item>
      <title>Real-time alerting with search head pooling</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Real-time-alerting-with-search-head-pooling/m-p/36607#M8130</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have a distributed environment with 2 search heads in a pool (for LB and HA) running v4.3.0 (upgrading shortly). &lt;BR /&gt;
When scheduling real-time searches, both search heads start processing the events simultaneously (There is splunkd search processes running on each search head).&lt;BR /&gt;
Then when an alert if fired, both search heads trigger the alert (for example, both search heads send an email; even with throttling enabled).&lt;/P&gt;

&lt;P&gt;1.Is it correct that both search heads run the scheduled real-time search? What is the benefit of this, as is just seems to put undue load on the environment?&lt;/P&gt;

&lt;P&gt;2.Is it possible to restrict this real-time searching to only occur on one or the two search heads?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Mark&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2012 04:48:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Real-time-alerting-with-search-head-pooling/m-p/36607#M8130</guid>
      <dc:creator>mark</dc:creator>
      <dc:date>2012-08-16T04:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Real-time alerting with search head pooling</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Real-time-alerting-with-search-head-pooling/m-p/36608#M8131</link>
      <description>&lt;P&gt;Sounds a bit strange. Real-time searches aren't that much different from normal searches and Splunk is taking care that only 1 search head in a pool is running each scheduled search. &lt;/P&gt;

&lt;P&gt;1) Search heads don't distribute jobs to another search heads but their search peers (aka indexers). If your search heads are also indexers then I suppose it's normal you see some activity on both systems.&lt;/P&gt;

&lt;P&gt;2) You can disable all scheduled searches on search head. I assume this would also disable real-time searches. See &lt;A href="http://splunk-base.splunk.com/answers/30640/how-does-search-head-pooling-work-with-scheduled-searches"&gt;"how does search head pooling work with scheduled searches?"&lt;/A&gt;&lt;BR /&gt;
This might act as work-a-round for you problem.&lt;/P&gt;

&lt;P&gt;BTW: Are you sure you aren't sending the same data to both your indexers? Ie. how did you verified both alerts were triggered from the same SINGLE event?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2012 05:33:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Real-time-alerting-with-search-head-pooling/m-p/36608#M8131</guid>
      <dc:creator>kallu</dc:creator>
      <dc:date>2012-08-16T05:33:14Z</dc:date>
    </item>
  </channel>
</rss>

