Hello All,
We currently have a single standalone deployment (index and search head on single system). In addition, we have deployed a new index cluster (3 nodes) and single search head. We will be migrating all of our forwarders to point to the newly deployed cluster. However, we still have data on the single deployment server that has not aged out yet. Does anyone know if it is possible to configure our search head to also search the old standalone Splunk environment ?
Thanks.
Yes, it is possible. Add the standalone instance as a search peer to the other search head. The new SH then will search both the cluster and the standalone.
Thanks, that worked perfectly!
Yes, it is possible. Add the standalone instance as a search peer to the other search head. The new SH then will search both the cluster and the standalone.