Splunk Enterprise Security

Multple Enterprise Security clusters to one search peer pool


Is it possible to have two instances of ES searching the same search peer pool?

Splunk Employee
Splunk Employee

It's 'possible' to install two, but I would not recommend doing so. The impact of running two ES Search Heads can have a catastrophic effect on the peers as you're running double the data model accelerations, plus all the other scheduled searches ES runs in the background.

If you want to set up a second ES node for testing (or similar) purposes, it's best to place it on a separate environment.

