Deployment Architecture

integrate standalone server into index cluster for search only

andymalato
Explorer

Hello All,

We currently have a single standalone deployment (index and search head on single system).  In addition, we have deployed a new index cluster (3 nodes) and single search head.  We will be migrating all of our forwarders to point to the newly deployed cluster.  However, we still have data on the single deployment server that has not aged out yet.   Does anyone know if it is possible to configure our search head to also search the old standalone Splunk environment ?  

 

Thanks.

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, it is possible.  Add the standalone instance as a search peer to the other search head.  The new SH then will search both the cluster and the standalone.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

andymalato
Explorer

Thanks, that worked perfectly!

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, it is possible.  Add the standalone instance as a search peer to the other search head.  The new SH then will search both the cluster and the standalone.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...