Deployment Architecture

Distributed Deployment

mandarpimplapur
Explorer

Dear Team,

We have a splunk 5.x version setup in our Office Environment as follows:

Splunk Server with "N" number of Forwarders.

Now, we need to add one new box with search heads and the splunk servers will act as Indexers.

Will it be possible ? Am i on right track.

Thanks in advance.

Tags (1)
0 Karma
1 Solution

gfreitas
Builder

Hi,

To add a Search Head to your installation, install Splunk Enterprise and follow the following procedure: http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Configuredistributedsearch.
Now, any search you run on your search head will be distributed to your search peers (Indexers).

View solution in original post

ddrillic
Ultra Champion

Makes perfect sense. The current server can function as the indexer and the new one(s) would be the search heads.

The best practice when moving from one Splunk server to multiple servers, is to keep the original server as the indexer, as you planned on doing.

alt text

gfreitas
Builder

Hi,

To add a Search Head to your installation, install Splunk Enterprise and follow the following procedure: http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Configuredistributedsearch.
Now, any search you run on your search head will be distributed to your search peers (Indexers).

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...