Splunk Cloud Platform

Additional Search Head for Splunk

anandhalagaras1
Contributor

Hi Team,

Currently we are using Splunk Cloud in our organization. i.e. We have a dedicated Search head for ES and another Adhoc search head for rest of the applications.

So we need an additional search head for development and testing purpose.  i.e. All the index logs should  be visible and searchable in the additional search head So do we need to contact Splunk Support on this  to host the same in Cloud and also we want to know will there be any cost involved as well.

Or else do we have any option something like that we can build a new server in Azure and install the Splunk  package into it (Additional Search Head) and can we integrate with Splunk Cloud so that all the index logs should be searchable & visible. So that before going directly into production we will perform a testing in the development environment.

We want a solution that should be cost effective since we majorly use it for development purpose.

Kindly help to address on my query.

 

 

Labels (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

I have Splunk cloud deployment in AWS and it's completely managed by Splunk cloud support.  I have never come across this problem ( this seems to be design & architecting problem). I hope definitely Splunk cloud supports to have one more instance in cloud, but I doubt if they allow you to connect to Splunk cloud indexers from your own Splunk Enterprise.

But, I would highly recommend you to create a Splunk support case. 

————————————
If this helps, give a like below.
0 Karma

thambisetty
SplunkTrust
SplunkTrust

Hope you have Splunk cloud support. I advise you to open a case with Splunk support. They will be able to give you quotation for that. 

————————————
If this helps, give a like below.
0 Karma

anandhalagaras1
Contributor

@thambisetty ,

Thank you for your response. But by any chance can we deploy a search head in on-prem (Azure) and integrate with Splunk Cloud?

Do you have any thoughts on it.

0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...