Getting Data In

How to set up an environment with an indexer on one machine and a search head on another?

ahmedhassanean
Explorer

Dears,

May I know please if it's possible to have a setup in which I will have only two machines: one of them will act as Indexer and the other to act as Search Head, and if it's possible, how can I achieve that?

thanks in advance

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, it is definitely possible and I've done it. Install Splunk on both machines. Make your search head a license master and the indexer a license slave. On the search head, go to Settings->Distributed Search->Search Peers and click the New button to add your indexer as a peer. Configure your inputs on the indexer. If you run universal forwarders, have them send data to the indexer.

See http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/Overviewofconfiguration for more information.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Yes, it is definitely possible and I've done it. Install Splunk on both machines. Make your search head a license master and the indexer a license slave. On the search head, go to Settings->Distributed Search->Search Peers and click the New button to add your indexer as a peer. Configure your inputs on the indexer. If you run universal forwarders, have them send data to the indexer.

See http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/Overviewofconfiguration for more information.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...