Deployment Architecture

Do I need to point a new search head to the master node or search peers of an indexer cluster?

saifuddin9122
Path Finder

Hello,

I have an indexer cluster setup. I don't want to configure a search head node in a cluster. I want to start a new Splunk Enterprise instance that I want to enable as a search head and search across the clustered indexers
1) is this possible?
2) if yes, can I see it in the master node dashboard?

Thanks,
SK

0 Karma
1 Solution

Steve_G_
Splunk Employee
Splunk Employee

It's a bit unclear from your question exactly what you want to do. I think that you're asking whether you can search the indexer cluster from a search head that's not part of a search head cluster. If that's your question, then, the answer is "yes, that's a standard configuration."

You do need to designate the search head as a node in the indexer cluster, however. See: http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Enablethesearchhead

View solution in original post

Steve_G_
Splunk Employee
Splunk Employee

It's a bit unclear from your question exactly what you want to do. I think that you're asking whether you can search the indexer cluster from a search head that's not part of a search head cluster. If that's your question, then, the answer is "yes, that's a standard configuration."

You do need to designate the search head as a node in the indexer cluster, however. See: http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Enablethesearchhead

saifuddin9122
Path Finder

Thanks for your answer
and sorry , my question was unclear.

0 Karma

prakash007
Builder
0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...