Getting Data In

Single Indexer with 2 different Search Heads?

Strype
Path Finder

Although I personally wouldn't want to set it up this way...

Is it possible to have one indexer that works for 2 separate search heads with 2 separate knowledge bundles? Wouldn't that cause a problem?

0 Karma

daniel_splunk
Splunk Employee
Splunk Employee

If you want both search head to use the common set of knowledge bundle, you need to configure Search head pooling.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

It is possible! However, any extractions that you want from one to the other need manually transferred. The data would be indexed in exactly the same way, but any Apps or search time modifications would be different.

Strype
Path Finder

Thanks so much!

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...