Deployment Architecture

Do I need to point a new search head to the master node or search peers of an indexer cluster?

saifuddin9122
Path Finder

Hello,

I have an indexer cluster setup. I don't want to configure a search head node in a cluster. I want to start a new Splunk Enterprise instance that I want to enable as a search head and search across the clustered indexers
1) is this possible?
2) if yes, can I see it in the master node dashboard?

Thanks,
SK

0 Karma
1 Solution

Steve_G_
Splunk Employee
Splunk Employee

It's a bit unclear from your question exactly what you want to do. I think that you're asking whether you can search the indexer cluster from a search head that's not part of a search head cluster. If that's your question, then, the answer is "yes, that's a standard configuration."

You do need to designate the search head as a node in the indexer cluster, however. See: http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Enablethesearchhead

View solution in original post

Steve_G_
Splunk Employee
Splunk Employee

It's a bit unclear from your question exactly what you want to do. I think that you're asking whether you can search the indexer cluster from a search head that's not part of a search head cluster. If that's your question, then, the answer is "yes, that's a standard configuration."

You do need to designate the search head as a node in the indexer cluster, however. See: http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Enablethesearchhead

saifuddin9122
Path Finder

Thanks for your answer
and sorry , my question was unclear.

0 Karma

prakash007
Builder
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...