Knowledge Management

Is there a way to separate indexer and search head apart?

muradgh
Path Finder

Hi Splunkers

I currently have one Splunk machine that has two rules at once (a search head and an indexer) and I want to separate each rule from another with its own separate machine.

Is there a way to do such action? if so, what are the steps to do so?

Thanks.

Labels (1)
Tags (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @muradgh,

you have to:

  • install a new server with the correct hardware reference,
  • install Splunk on it,
  • configurate it to work with a Forwarder license,
  • forward all logs to the other server,
  • configure it as Searche Haed that uses the other server
  • use it for the searches.

for more information you can see at https://docs.splunk.com/Documentation/Splunk/9.0.2/DistSearch/Whatisdistributedsearch

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @muradgh,

you have to:

  • install a new server with the correct hardware reference,
  • install Splunk on it,
  • configurate it to work with a Forwarder license,
  • forward all logs to the other server,
  • configure it as Searche Haed that uses the other server
  • use it for the searches.

for more information you can see at https://docs.splunk.com/Documentation/Splunk/9.0.2/DistSearch/Whatisdistributedsearch

Ciao.

Giuseppe

muradgh
Path Finder

Thank you @gcusello ^^

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @muradgh,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...