Deployment Architecture

integrate standalone server into index cluster for search only

andymalato
Explorer

Hello All,

We currently have a single standalone deployment (index and search head on single system).  In addition, we have deployed a new index cluster (3 nodes) and single search head.  We will be migrating all of our forwarders to point to the newly deployed cluster.  However, we still have data on the single deployment server that has not aged out yet.   Does anyone know if it is possible to configure our search head to also search the old standalone Splunk environment ?  

 

Thanks.

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, it is possible.  Add the standalone instance as a search peer to the other search head.  The new SH then will search both the cluster and the standalone.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

andymalato
Explorer

Thanks, that worked perfectly!

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, it is possible.  Add the standalone instance as a search peer to the other search head.  The new SH then will search both the cluster and the standalone.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...