Getting Data In

Could I install a search head and an indexer on different operating systems?

Afef
Communicator

Hello,

I have one Splunk instance (Windows) and I would like to add a Linux search head for the indexer. Could I do this? Will this cause problems?

Thanks

woodcock
Esteemed Legend

You can mix-and match HW and OS anywhere and it should work fine. The only exception is that if you use a Windows Deployment Server for Linux Forwarders, you are likely to have problems with permissions.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

There is one other notable exception: If you are using indexer clustering, all indexers must be at the same OS flavor and version AND Splunk needs to be at the exact same version on all peer nodes as well.
So you can't have five Windows boxes and two Linux servers be part of a cluster. But no sane person would consider doing that anyway....
I would generally try to stick with a homogeneous search, indexing & management environment as much as possible (preferably Linux) for all kinds of reasons.

0 Karma

Afef
Communicator

No, i have one indexer (windows) and i would add a linux search head, is this possible ?

0 Karma

MuS
SplunkTrust
SplunkTrust

Yes, it is possible.

0 Karma

Afef
Communicator

No, i have a windows indexer which contains also the deployment server and i would like to add a linux search head for the entreprise security app

0 Karma

javiergn
SplunkTrust
SplunkTrust

Isn't the Windows Deployment Server for Linux Forwarders even worse? That's what we had in my last place and it was breaking the permission model every single time a deployment was made, so we ended up scripting a fix for it.

I thought this wasn't the case on a Linux Deployment Server for Windows Forwarders?

What is the alternative then? Have two deployment servers one for Windows and one for Linux?

Thanks,
Javier

woodcock
Esteemed Legend

You are correct, I said it backwards. I went back and fixed my answer.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

This is fully supported. Refer to the documentation on configuring distributed search in order for your SH to use the indexer.

Afef
Communicator

thank you for your answer, i did not found the information in splunk docs.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...