Splunk Enterprise

indexer and search head on the same server

jiaqya
Builder

is it possible to run both indexer and search head on the same splunk server.
i kind of have only one server in one of my test environments, so was wondering if this was an option as i am having dbconnect on that server.

im unable to add the search peer as itself..

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, this is common in small environments and test/dev systems. Install a single instance of Splunk and it will function as both search head and indexer. There is no need to configure distributed search in this case.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jiaqya
Builder

Thanks Galloway, but i am not sure why my dbconnect is able to see data in the splunk db connect app ,but its not indexing it then..
any ideas...

0 Karma

jiaqya
Builder

Strange, its all working after i reinstalled it..

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@jiaqya If your problem is resolved, please accept the answer to help future readers.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...