If a Splunk Search Head image is destroyed, but the rest of the servers/components are up and running including the Deployment, Indexers, HWF and License server. Would it be possible to rebuild just the Search Head or does the entire Splunk environment need to be rebuilt?
Hi @CyberGuy1033,
you can create a fresh Splunk installation and configure it as Search Head connecting it to your Indexers.
Ciao.
Giuseppe
The search head alone can be replaced/rebuilt.