Dear Team,
We have a splunk 5.x version setup in our Office Environment as follows:
Splunk Server with "N" number of Forwarders.
Now, we need to add one new box with search heads and the splunk servers will act as Indexers.
Will it be possible ? Am i on right track.
Thanks in advance.
Hi,
To add a Search Head to your installation, install Splunk Enterprise and follow the following procedure: http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Configuredistributedsearch.
Now, any search you run on your search head will be distributed to your search peers (Indexers).
Hi,
To add a Search Head to your installation, install Splunk Enterprise and follow the following procedure: http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Configuredistributedsearch.
Now, any search you run on your search head will be distributed to your search peers (Indexers).