Hello Splunk Community,
I am working on the configuration of a distributed Splunk deployment, and I need clarification regarding the KV Store. Could you please confirm where the KV Store should be configured in a distributed environment?
Should it be enabled on the Search Heads, Indexers, or another component of the deployment? Any guidance on best practices would be greatly appreciated.
Thank you for your help!
Best regards,
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Hi @BRFZ ,
KV-Store is usually enabled only on Search Heads and disabled on the other roles (Indexers, Heavy Forwarders, et...)
Ciao.
Giuseppe
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Hi @BRFZ ,
KV-Store is usually enabled only on Search Heads and disabled on the other roles (Indexers, Heavy Forwarders, et...)
Ciao.
Giuseppe
