Hello Splunk Community,
I am working on the configuration of a distributed Splunk deployment, and I need clarification regarding the KV Store. Could you please confirm where the KV Store should be configured in a distributed environment?
Should it be enabled on the Search Heads, Indexers, or another component of the deployment? Any guidance on best practices would be greatly appreciated.
Thank you for your help!
Best regards,
Hi @BRFZ ,
KV-Store is usually enabled only on Search Heads and disabled on the other roles (Indexers, Heavy Forwarders, et...)
Ciao.
Giuseppe
Hi @BRFZ ,
KV-Store is usually enabled only on Search Heads and disabled on the other roles (Indexers, Heavy Forwarders, et...)
Ciao.
Giuseppe