Getting Data In

How to set up an environment with an indexer on one machine and a search head on another?

ahmedhassanean
Explorer

Dears,

May I know please if it's possible to have a setup in which I will have only two machines: one of them will act as Indexer and the other to act as Search Head, and if it's possible, how can I achieve that?

thanks in advance

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, it is definitely possible and I've done it. Install Splunk on both machines. Make your search head a license master and the indexer a license slave. On the search head, go to Settings->Distributed Search->Search Peers and click the New button to add your indexer as a peer. Configure your inputs on the indexer. If you run universal forwarders, have them send data to the indexer.

See http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/Overviewofconfiguration for more information.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Yes, it is definitely possible and I've done it. Install Splunk on both machines. Make your search head a license master and the indexer a license slave. On the search head, go to Settings->Distributed Search->Search Peers and click the New button to add your indexer as a peer. Configure your inputs on the indexer. If you run universal forwarders, have them send data to the indexer.

See http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/Overviewofconfiguration for more information.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...