Deployment Architecture

Do I need to point a new search head to the master node or search peers of an indexer cluster?

saifuddin9122
Path Finder

Hello,

I have an indexer cluster setup. I don't want to configure a search head node in a cluster. I want to start a new Splunk Enterprise instance that I want to enable as a search head and search across the clustered indexers
1) is this possible?
2) if yes, can I see it in the master node dashboard?

Thanks,
SK

0 Karma
1 Solution

Steve_G_
Splunk Employee
Splunk Employee

It's a bit unclear from your question exactly what you want to do. I think that you're asking whether you can search the indexer cluster from a search head that's not part of a search head cluster. If that's your question, then, the answer is "yes, that's a standard configuration."

You do need to designate the search head as a node in the indexer cluster, however. See: http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Enablethesearchhead

View solution in original post

Steve_G_
Splunk Employee
Splunk Employee

It's a bit unclear from your question exactly what you want to do. I think that you're asking whether you can search the indexer cluster from a search head that's not part of a search head cluster. If that's your question, then, the answer is "yes, that's a standard configuration."

You do need to designate the search head as a node in the indexer cluster, however. See: http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Enablethesearchhead

saifuddin9122
Path Finder

Thanks for your answer
and sorry , my question was unclear.

0 Karma

prakash007
Builder
0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...