Splunk Enterprise Security

Having a separate ES search head from a general search head

hopnscotch
Path Finder

Is it possible/ok to have 1 search head running ES and one without? We will have a large number of overall users but only 7-8 using the ES app. I'm trying to avoid search head pooling if possible.

Any thoughts around this are welcome. Thanks

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

it means separate from other search heads. This can be confusing in a small instance where you don't need to distinguish between search heads and indexers, but once you go to "pool of indexers with search heads floating on top" it starts getting clearer.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

It's more the other way around -- a separate search head is the recommendation / requirement, but it's possible to run other apps on there as well.

0 Karma

hopnscotch
Path Finder

I did read that a separate SH is required. The way that is worded is confusing those.. separate from what? indexers or other search heads?

I will have a separate index cluster. My question is if there are any issues with having a search head that is NOT running ES along side one that is searching the same indexers. I guess the only other thing that ties them together is the license so just wondering if there are any issues with this scenario.

Thanks

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...