Splunk Enterprise Security

Having a separate ES search head from a general search head

hopnscotch
Path Finder

Is it possible/ok to have 1 search head running ES and one without? We will have a large number of overall users but only 7-8 using the ES app. I'm trying to avoid search head pooling if possible.

Any thoughts around this are welcome. Thanks

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

it means separate from other search heads. This can be confusing in a small instance where you don't need to distinguish between search heads and indexers, but once you go to "pool of indexers with search heads floating on top" it starts getting clearer.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

It's more the other way around -- a separate search head is the recommendation / requirement, but it's possible to run other apps on there as well.

0 Karma

hopnscotch
Path Finder

I did read that a separate SH is required. The way that is worded is confusing those.. separate from what? indexers or other search heads?

I will have a separate index cluster. My question is if there are any issues with having a search head that is NOT running ES along side one that is searching the same indexers. I guess the only other thing that ties them together is the license so just wondering if there are any issues with this scenario.

Thanks

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...