Getting Data In

How to set up an environment with an indexer on one machine and a search head on another?

ahmedhassanean
Explorer

Dears,

May I know please if it's possible to have a setup in which I will have only two machines: one of them will act as Indexer and the other to act as Search Head, and if it's possible, how can I achieve that?

thanks in advance

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, it is definitely possible and I've done it. Install Splunk on both machines. Make your search head a license master and the indexer a license slave. On the search head, go to Settings->Distributed Search->Search Peers and click the New button to add your indexer as a peer. Configure your inputs on the indexer. If you run universal forwarders, have them send data to the indexer.

See http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/Overviewofconfiguration for more information.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Yes, it is definitely possible and I've done it. Install Splunk on both machines. Make your search head a license master and the indexer a license slave. On the search head, go to Settings->Distributed Search->Search Peers and click the New button to add your indexer as a peer. Configure your inputs on the indexer. If you run universal forwarders, have them send data to the indexer.

See http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/Overviewofconfiguration for more information.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...