Splunk Enterprise Security

Splunk PCI Installation of indexes

cafissimo
Communicator

Hello,
I am installing Splunk PCI app 3.5.0 on an environment that is made of a Search Head and two indexers (not clustered).
Should I forward all data from Search Head to the indexers (as best practices say) or should I let the Search Head index something?

Thanks in advance and kind regards.

0 Karma

xpac
SplunkTrust
SplunkTrust

Always forward all the data to the indexers.
Indexers gonna index, Search heads gonna search 😉

Seriously, indexers are built to store the data, you can cluster them, so the data is replicated, etc. Even if they're not clustered - that's where the data belongs. You'll just get yourself in unsupported trouble 😉
Search heads, even clustered, do not replicate their indexed data, because that's not what they're designed for.
Therefore - follow best practice, please.

Hope that helps - if it does I'd be happy if you would upvote/accept this answer, so others could profit from it. 🙂

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...