Getting Data In

How to enable this standalone search head(SH) to search data in a clustered SH/indexer?

krusovice
Path Finder

Hi all,

I have the distributed environment setup for SH cluster and indexer cluster.

Now, I have a standalone server with both SH and indexer configured. My question is how to enable this standalone server to search the data ingested to distributed/clustered environment?

I just want to enable the search in standalone server, and I don't want to have the data inside standalone server, and I don't want to add standalone as one of the SH cluster.

Is this doable? I'm trying to read the documentation but kind of confusing after reading and I have no idea which document is the right doc for such requirement.

Thanks.

0 Karma
1 Solution

DalJeanis
Legend

Yes, it is doable.

A search head can search multiple indexers. It can also search multiple indexer clusters. Here's one answer that talks about that...

https://answers.splunk.com/answers/65766/configure-one-search-head-to-search-multiple-clusters-each-...

Annnnddd.... here's the specific page with careful instructions for what you are asking...

https://docs.splunk.com/Documentation/Splunk/7.1.1/Indexer/Configureclusteredandnonclusteredsearch

The search head will have a distsearch.conf file with the unclustered indexers in it, and server.conf with the cluster master described in it for the clustered indexers.

Please read the description carefully, at least three times before you touch the keyboard.

View solution in original post

0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

Hello @krusovice . Were you able to test out @DalJeanis 's solution? Did it work? If yes, please don't forget to resolve this post by clicking on "Accept". If you still need more help, please provide a comment with some feedback. Thanks!

0 Karma

DalJeanis
Legend

Yes, it is doable.

A search head can search multiple indexers. It can also search multiple indexer clusters. Here's one answer that talks about that...

https://answers.splunk.com/answers/65766/configure-one-search-head-to-search-multiple-clusters-each-...

Annnnddd.... here's the specific page with careful instructions for what you are asking...

https://docs.splunk.com/Documentation/Splunk/7.1.1/Indexer/Configureclusteredandnonclusteredsearch

The search head will have a distsearch.conf file with the unclustered indexers in it, and server.conf with the cluster master described in it for the clustered indexers.

Please read the description carefully, at least three times before you touch the keyboard.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...