Splunk Enterprise

Is there a difference placing a saved search for example on ES or on a search head? Thank u in advance.

SamHTexas
Builder

Is there a difference placing a saved search on for example on ES or on a search head?  What would be the consequences? What are saved searches "Best practices" ? Thank u in advance.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

To be pedantic, ES *is* a search head so the question is *which* SH should run the search.  If the search is related to ES (uses ES KOs, updates lookups, creates notable events, etc.) then it should run on the ES SH.  All other searches should run on a different SH.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...