Splunk Enterprise Security
Highlighted

Having a separate ES search head from a general search head

Path Finder

Is it possible/ok to have 1 search head running ES and one without? We will have a large number of overall users but only 7-8 using the ES app. I'm trying to avoid search head pooling if possible.

Any thoughts around this are welcome. Thanks

0 Karma
Highlighted

Re: Having a separate ES search head from a general search head

Splunk Employee
Splunk Employee

It's more the other way around -- a separate search head is the recommendation / requirement, but it's possible to run other apps on there as well.

0 Karma
Highlighted

Re: Having a separate ES search head from a general search head

Path Finder

I did read that a separate SH is required. The way that is worded is confusing those.. separate from what? indexers or other search heads?

I will have a separate index cluster. My question is if there are any issues with having a search head that is NOT running ES along side one that is searching the same indexers. I guess the only other thing that ties them together is the license so just wondering if there are any issues with this scenario.

Thanks

0 Karma
Highlighted

Re: Having a separate ES search head from a general search head

Splunk Employee
Splunk Employee

it means separate from other search heads. This can be confusing in a small instance where you don't need to distinguish between search heads and indexers, but once you go to "pool of indexers with search heads floating on top" it starts getting clearer.

0 Karma