Splunk Enterprise Security

Search Head Pooling v. Search Head Clustering

hberkis
New Member

If i am running Splunnk 6.2.x and ES 3.x using search head pooling, and I upgrade to Splunk 6.3.1 and ES 4.0.1 using search head pooling;
* is this supported
* will this cause problems? performance issues, etc.

0 Karma

hberkis
New Member

Can anyone guess what the impact would be if this were implemented?

0 Karma

somesoni2
Revered Legend

Are you using native Splunk SH pooling OR custom?

0 Karma

hberkis
New Member

We are using native sh pooling.

0 Karma

somesoni2
Revered Legend

Well, native SH Pooling is not supported by ES 4.0.1, as mentioned by @schose. But SH Cluster is supported (on Linux Platform), so consider migrating to the same.

0 Karma

schose
Builder

ES 4.x does not support searchhead pooling
"Splunk Enterprise Security does not support search head pooling."

http://docs.splunk.com/Documentation/ES/4.0.1/Install/DeploymentPlanning

Regards,

Andreas

Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...