Is it best practice to copy the /search/local directory to the new search head cluster members and not use the deployer? I used a deployer to set up LDAP, but per documentation, it says not to do the same for the search application.
Per Documentation:
The types of updates that the deployer handles
These are the specific types of updates that require the deployer:
Do not use the Deployer to update the apps that come with Splunk: search, launcher, etc. Here is an answer that should help, along with a link to the documentation
Migrate from a standalone searchheads
Migrating separate environments to SHC
I guess that you could do this manually, without the deployer, but it would be hard and error-prone. IMO, the method described in the doc/answer will work better.
Do not use the Deployer to update the apps that come with Splunk: search, launcher, etc. Here is an answer that should help, along with a link to the documentation
Migrate from a standalone searchheads
Migrating separate environments to SHC
I guess that you could do this manually, without the deployer, but it would be hard and error-prone. IMO, the method described in the doc/answer will work better.