Security

Search Heads in bigip pool- License usage

pdash
Path Finder

We have two search heads that are in big ip pool. One of them is master. When doing a license alert set up, it gets set up in both the search head and returns result from search heads randomly ending up giving no result some times when it queries the slave. how to avoid this?

Tags (1)
0 Karma

dart
Splunk Employee
Splunk Employee

If you have loadbalanced search heads they should be set up in a search head pool. This will ensure that scheduled searches run on one node in the pool.

See the documentation on search head pooling.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...