Hello to the community!
I was wondering if there is any best practices regarding the removal of Search Head role from an indexer and moving it to a new server. I have started as a "demo" installation with a machine with indexer and SH role, so I need to remove all activities of the SH and move them to the new machine. Is there any documentation on performing such task? The SH also contains Enterprise Security App.
Thanks,
Andreas
Hi Andreas,
If you would like to have dedicated search heard, following steps might help you
Once you have the "new" search head installed, copy the searches and apps to the new search head
Setting » Server settings » General settings
and select "No" for 'Run Splunk Web' [ or from cmd line ./splunk disable webserver
]Lets know in case you have further questions.
Hi Andreas,
If you would like to have dedicated search heard, following steps might help you
Once you have the "new" search head installed, copy the searches and apps to the new search head
Setting » Server settings » General settings
and select "No" for 'Run Splunk Web' [ or from cmd line ./splunk disable webserver
]Lets know in case you have further questions.
Thank you very much for your answer!
One more question: how I can offload the indexer from the SH tasks? Delete enterprise security?
Added the steps. In short, once you move the scheduled searches to the new search most of the load should be offloaded.