Getting Data In

How to set up an environment with an indexer on one machine and a search head on another?

ahmedhassanean
Explorer

Dears,

May I know please if it's possible to have a setup in which I will have only two machines: one of them will act as Indexer and the other to act as Search Head, and if it's possible, how can I achieve that?

thanks in advance

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, it is definitely possible and I've done it. Install Splunk on both machines. Make your search head a license master and the indexer a license slave. On the search head, go to Settings->Distributed Search->Search Peers and click the New button to add your indexer as a peer. Configure your inputs on the indexer. If you run universal forwarders, have them send data to the indexer.

See http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/Overviewofconfiguration for more information.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Yes, it is definitely possible and I've done it. Install Splunk on both machines. Make your search head a license master and the indexer a license slave. On the search head, go to Settings->Distributed Search->Search Peers and click the New button to add your indexer as a peer. Configure your inputs on the indexer. If you run universal forwarders, have them send data to the indexer.

See http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/Overviewofconfiguration for more information.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...