Splunk Enterprise Security

Does Enterprise Security work just fine with a search head cluster?

danielbb
Motivator

We read someplace that ES and the SH cluster might be tricky.

It is right? or ES works naturally with the SH cluster?

0 Karma

skalliger
Motivator

Hi,

that depends what version you are referring to.

Starting with Enterprise Security 5.3.0, the installer of ES has changed, look into the Release Notes for further information.

In the past, you needed a staging server for ES in a SHC. Now you can use a deployer for initial installing and upgrades of ES.

Skalli

danielbb
Motivator

Looks great -

alt text

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...