Hello everyone.
Currently I have a cluster architecture of Splunk Enterprise 8.0.7.
Now I have to deploy Splunk Security over that architecture.
Is that possible?
Thanks in advance.
Thanks for your answer @richgalloway
So, Can I have a SH as a standalone and install in that search head the App, and connect the SH standalone with the indexer cluster?
Thanks in advance
Thanks for your answer @richgalloway
So, Can I have a SH as a standalone and install in that search head the App, and connect the SH standalone with the indexer cluster?
Thanks in advance
Yes, you can run ES on a standalone Windows SH connected to an indexer cluster, although I think you'll be happier running ES on Linux.
Thank you for the useful help @richgalloway
Yes, I know in linux works much better, but for now that's what I have...
Thanks again.
Windows SHCs are not supported. See https://docs.splunk.com/Documentation/ES/6.4.0/Install/InstallEnterpriseSecuritySHC#Prerequisites_fo...