Hello guys,
is adding standalone search head in existing sh cluster without conf configuration replications supported by Splunk?
We have a sh searching clustered indexers with specific configuration and we don't want it inherits shcluster updates (like sh apps or auth)
We tested distributed search but we had duplicate events.
This separated sh hasn't conf_deploy_fetch_url set.
Thanks.
Hi @realsplunk,
yes you can, you have to connect it to the Indexer Cluster as usual.
See https://docs.splunk.com/Documentation/Splunk/8.0.0/Indexer/Configurethesearchhead
Ciao.
Giuseppe