Splunk Enterprise Security

Search Head Pooling v. Search Head Clustering

New Member

If i am running Splunnk 6.2.x and ES 3.x using search head pooling, and I upgrade to Splunk 6.3.1 and ES 4.0.1 using search head pooling;
* is this supported
* will this cause problems? performance issues, etc.

0 Karma

New Member

Can anyone guess what the impact would be if this were implemented?

0 Karma

SplunkTrust
SplunkTrust

Are you using native Splunk SH pooling OR custom?

0 Karma

New Member

We are using native sh pooling.

0 Karma

SplunkTrust
SplunkTrust

Well, native SH Pooling is not supported by ES 4.0.1, as mentioned by @schose. But SH Cluster is supported (on Linux Platform), so consider migrating to the same.

0 Karma

Contributor

ES 4.x does not support searchhead pooling
"Splunk Enterprise Security does not support search head pooling."

http://docs.splunk.com/Documentation/ES/4.0.1/Install/DeploymentPlanning

Regards,

Andreas