Knowledge Management

Is there a way to separate indexer and search head apart?

muradgh
Path Finder

Hi Splunkers

I currently have one Splunk machine that has two rules at once (a search head and an indexer) and I want to separate each rule from another with its own separate machine.

Is there a way to do such action? if so, what are the steps to do so?

Thanks.

Labels (1)
Tags (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @muradgh,

you have to:

  • install a new server with the correct hardware reference,
  • install Splunk on it,
  • configurate it to work with a Forwarder license,
  • forward all logs to the other server,
  • configure it as Searche Haed that uses the other server
  • use it for the searches.

for more information you can see at https://docs.splunk.com/Documentation/Splunk/9.0.2/DistSearch/Whatisdistributedsearch

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @muradgh,

you have to:

  • install a new server with the correct hardware reference,
  • install Splunk on it,
  • configurate it to work with a Forwarder license,
  • forward all logs to the other server,
  • configure it as Searche Haed that uses the other server
  • use it for the searches.

for more information you can see at https://docs.splunk.com/Documentation/Splunk/9.0.2/DistSearch/Whatisdistributedsearch

Ciao.

Giuseppe

muradgh
Path Finder

Thank you @gcusello ^^

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @muradgh,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...