- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear Team,
We have a splunk 5.x version setup in our Office Environment as follows:
Splunk Server with "N" number of Forwarders.
Now, we need to add one new box with search heads and the splunk servers will act as Indexers.
Will it be possible ? Am i on right track.
Thanks in advance.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
To add a Search Head to your installation, install Splunk Enterprise and follow the following procedure: http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Configuredistributedsearch.
Now, any search you run on your search head will be distributed to your search peers (Indexers).
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Makes perfect sense. The current server can function as the indexer and the new one(s) would be the search heads.
The best practice when moving from one Splunk server to multiple servers, is to keep the original server as the indexer, as you planned on doing.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
To add a Search Head to your installation, install Splunk Enterprise and follow the following procedure: http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Configuredistributedsearch.
Now, any search you run on your search head will be distributed to your search peers (Indexers).
