Deployment Architecture

Do I need to point a new search head to the master node or search peers of an indexer cluster?

saifuddin9122
Path Finder

Hello,

I have an indexer cluster setup. I don't want to configure a search head node in a cluster. I want to start a new Splunk Enterprise instance that I want to enable as a search head and search across the clustered indexers
1) is this possible?
2) if yes, can I see it in the master node dashboard?

Thanks,
SK

0 Karma
1 Solution

Steve_G_
Splunk Employee
Splunk Employee

It's a bit unclear from your question exactly what you want to do. I think that you're asking whether you can search the indexer cluster from a search head that's not part of a search head cluster. If that's your question, then, the answer is "yes, that's a standard configuration."

You do need to designate the search head as a node in the indexer cluster, however. See: http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Enablethesearchhead

View solution in original post

Steve_G_
Splunk Employee
Splunk Employee

It's a bit unclear from your question exactly what you want to do. I think that you're asking whether you can search the indexer cluster from a search head that's not part of a search head cluster. If that's your question, then, the answer is "yes, that's a standard configuration."

You do need to designate the search head as a node in the indexer cluster, however. See: http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Enablethesearchhead

saifuddin9122
Path Finder

Thanks for your answer
and sorry , my question was unclear.

0 Karma

prakash007
Builder
0 Karma
Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...

New Splunk Innovations Enhance Performance and Accelerate Troubleshooting

Splunk is excited to announce new releases that empower ITOps and engineering teams to stay ahead in ever ...