Splunk Enterprise Security

Search Head Pooling v. Search Head Clustering

New Member

If i am running Splunnk 6.2.x and ES 3.x using search head pooling, and I upgrade to Splunk 6.3.1 and ES 4.0.1 using search head pooling;
* is this supported
* will this cause problems? performance issues, etc.

0 Karma

New Member

Can anyone guess what the impact would be if this were implemented?

0 Karma

Revered Legend

Are you using native Splunk SH pooling OR custom?

0 Karma

New Member

We are using native sh pooling.

0 Karma

Revered Legend

Well, native SH Pooling is not supported by ES 4.0.1, as mentioned by @schose. But SH Cluster is supported (on Linux Platform), so consider migrating to the same.

0 Karma

Contributor

ES 4.x does not support searchhead pooling
"Splunk Enterprise Security does not support search head pooling."

http://docs.splunk.com/Documentation/ES/4.0.1/Install/DeploymentPlanning

Regards,

Andreas

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!