Getting Data In

How to add a search head to search against our Splunk indexer?

kairobin
Path Finder

What are the best practices for setup and using a search head server to take the load off of our indexer?
We have an enterprise license. Do you have a how-to somewhere for adding another search head
and how is the licensing being added to the enterprise license?

0 Karma

MuS
Legend

Hi kairobin,

take a look at the docs here http://docs.splunk.com/Documentation/Splunk/6.2.2/DistSearch/Overviewofconfiguration to get more details how it can be done.
Regarding the license; you can configure the search head as license slave http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/Configurealicenseslave , but usually the search head will not consume any license volume since it will not index any data.

Hope this helps ...

cheers, MuS

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...