Knowledge Management

Is there a way to separate indexer and search head apart?

muradgh
Path Finder

Hi Splunkers

I currently have one Splunk machine that has two rules at once (a search head and an indexer) and I want to separate each rule from another with its own separate machine.

Is there a way to do such action? if so, what are the steps to do so?

Thanks.

Tags (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @muradgh,

you have to:

  • install a new server with the correct hardware reference,
  • install Splunk on it,
  • configurate it to work with a Forwarder license,
  • forward all logs to the other server,
  • configure it as Searche Haed that uses the other server
  • use it for the searches.

for more information you can see at https://docs.splunk.com/Documentation/Splunk/9.0.2/DistSearch/Whatisdistributedsearch

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @muradgh,

you have to:

  • install a new server with the correct hardware reference,
  • install Splunk on it,
  • configurate it to work with a Forwarder license,
  • forward all logs to the other server,
  • configure it as Searche Haed that uses the other server
  • use it for the searches.

for more information you can see at https://docs.splunk.com/Documentation/Splunk/9.0.2/DistSearch/Whatisdistributedsearch

Ciao.

Giuseppe

muradgh
Path Finder

Thank you @gcusello ^^

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @muradgh,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...