Deployment Architecture

Setup Alert on Single SH when in a Shared Pool

pdash
Path Finder

How to set up an alert that runs only on one SH if we have more than one SH in a pool. We have 2 SH one is master and one slave. I want to run a license usage alert that should run only on the master. How should I configure this so that every time it only runs on the master server?

Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

no, this is exactly the purpose of the search-head pooling feature,
if you have 2 SH in a pool, only one will run the scheduled search. (they use a lock on the shared dispatch folder to avoid running it twice)

If you really need to have a SH that do not share searches, create a dedicated SH outside of the pool.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...