Getting Data In

Single Indexer with 2 different Search Heads?

Strype
Path Finder

Although I personally wouldn't want to set it up this way...

Is it possible to have one indexer that works for 2 separate search heads with 2 separate knowledge bundles? Wouldn't that cause a problem?

0 Karma

daniel_splunk
Splunk Employee
Splunk Employee

If you want both search head to use the common set of knowledge bundle, you need to configure Search head pooling.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

It is possible! However, any extractions that you want from one to the other need manually transferred. The data would be indexed in exactly the same way, but any Apps or search time modifications would be different.

Strype
Path Finder

Thanks so much!

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...