Deployment Architecture

Does splunk support running a standalone search head next to a search head cluster?

chustar
Path Finder

While reading the guide for upgrading stand alone search heads to a cluster, I noticed that you cannot add an existing search head.

It must be a new instance, or cleaned using splunk clean all,

Because our one instance had many custom scripts and settings, I don't want to wipe and upgrade this cluster yet, could this existing instance be used alongside (but separate from) the search head cluster?

1 Solution

cpetterborg
SplunkTrust
SplunkTrust

You should be able to keep the standalone SH a standalone SH and search off the existing Index cluster. Just point the searchhead at the cluster. We have a standalone SH apart from our SHC for apps like DBConnect and the Service Now app.

View solution in original post

splunkreal
Motivator

Hello,

we want to migrate our existing SH (also deployment server for UF) and standalone IDX to SHC / clustered indexers by adding new VMs.

This looks good idea to setup the new cluster first then how to add old SH/IDX?

Thanks for your help.

 

* If this helps, please upvote or accept solution if it solved *
0 Karma

cpetterborg
SplunkTrust
SplunkTrust

You should be able to keep the standalone SH a standalone SH and search off the existing Index cluster. Just point the searchhead at the cluster. We have a standalone SH apart from our SHC for apps like DBConnect and the Service Now app.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...