Installation

Add a standalone search head

jwilliams
Explorer

Hello,

  I have a single splunk indexer.   How do I add a search head?   I do not have an index cluster.  At this time I have a single indexer but may go to two indexers.   Documentation talks about index cluster which I do not have.

  My simple goal was to have a search head and a indexer or two indexers.

  This is a new user type question running version 8.

Thanks in Advance,

Jim

Tags (1)
0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

https://docs.splunk.com/Documentation/Splunk/8.0.5/DistSearch/Configuredistributedsearch

Probably the easiest way to do this is via the Search Head's WebGUI. Log in as an admin, and go to Settings > Distributed Search. Then click on Search Peers. Provide your indexer's IP or FQDN, https://indexer_address:8089 and admin credentials for the indexer. Click Save, and you will have linked the search head with the indexer.

You can also use CLI or .conf files to do so, but I think the WebGUI illustrates it best.

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...