Deployment Architecture

to establish connection between Indexer and searchhead

VijaySrrie
Builder

Hi,
During first time setup how to establish a connection between indexer and search head?
In forwarder we are giving indexer names in outputs.conf so a connection is established between forwarder and indexer. In the same way how to establish a connection between indexer and searchhead?

Labels (3)
Tags (1)
0 Karma
1 Solution

DavidHourani
Super Champion

Hi @vijaysri,

If you want to connect a standalone indexer to your search head you can add it as a search peer as follows :
https://docs.splunk.com/Documentation/Splunk/8.0.3/DistSearch/Configuredistributedsearch

If you want to connect an indexer cluster to your search head then you should connect your search head to the cluster master as follows :
https://docs.splunk.com/Documentation/Splunk/8.0.3/Indexer/Enablethesearchhead

Let me know if this helps !

Cheers,
David

View solution in original post

0 Karma

DavidHourani
Super Champion

Hi @vijaysri,

If you want to connect a standalone indexer to your search head you can add it as a search peer as follows :
https://docs.splunk.com/Documentation/Splunk/8.0.3/DistSearch/Configuredistributedsearch

If you want to connect an indexer cluster to your search head then you should connect your search head to the cluster master as follows :
https://docs.splunk.com/Documentation/Splunk/8.0.3/Indexer/Enablethesearchhead

Let me know if this helps !

Cheers,
David

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...