Deployment Architecture

Has anyone made a search head a search peer of another search head?

Runals
Motivator

We have a number of non pooled search heads and are contemplating making them search peers to our main admin search head. The primary use case is to support REST commands on things like saved searches, user permissions, etc that we can run within the search bar. The concern is the implication of general searches from this admin box (light use) on the downstream search heads. At some level I wonder if it would simply come down to the number of cores on those systems.

0 Karma

cpride_splunk
Splunk Employee
Splunk Employee

You want to be aware of load but in general this should be possible. There are cases that will break. (Notably this is not a supported configuration with Search Head Clustering in 6.2) This is however how the DMC app in 6.2 works.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...