Splunk Enterprise Security

Having a separate ES search head from a general search head

hopnscotch
Path Finder

Is it possible/ok to have 1 search head running ES and one without? We will have a large number of overall users but only 7-8 using the ES app. I'm trying to avoid search head pooling if possible.

Any thoughts around this are welcome. Thanks

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

it means separate from other search heads. This can be confusing in a small instance where you don't need to distinguish between search heads and indexers, but once you go to "pool of indexers with search heads floating on top" it starts getting clearer.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

It's more the other way around -- a separate search head is the recommendation / requirement, but it's possible to run other apps on there as well.

0 Karma

hopnscotch
Path Finder

I did read that a separate SH is required. The way that is worded is confusing those.. separate from what? indexers or other search heads?

I will have a separate index cluster. My question is if there are any issues with having a search head that is NOT running ES along side one that is searching the same indexers. I guess the only other thing that ties them together is the license so just wondering if there are any issues with this scenario.

Thanks

0 Karma
Get Updates on the Splunk Community!

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more with ITSI’s ...

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more! Faster Time to ValueManaging and ...

New Release | Splunk Enterprise 9.3

Admins and Analyst can benefit from:  Seamlessly route data to your local file system to save on storage ...

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...