Getting Data In

How to add a search head to search against our Splunk indexer?

Path Finder

What are the best practices for setup and using a search head server to take the load off of our indexer?
We have an enterprise license. Do you have a how-to somewhere for adding another search head
and how is the licensing being added to the enterprise license?

0 Karma


Hi kairobin,

take a look at the docs here to get more details how it can be done.
Regarding the license; you can configure the search head as license slave , but usually the search head will not consume any license volume since it will not index any data.

Hope this helps ...

cheers, MuS

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!