Splunk Search

Add clustered search peers (indexers) to standalone search head?

splunkreal
Motivator

Hello,

is it possible to add clustered search peers (indexers) to standalone search head?

Thanks.

* If this helps, please upvote or accept solution 🙂 *
0 Karma

somesoni2
Revered Legend

Yes, follow below instructions to add a search head to query Indexer cluster.

http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Enablethesearchhead#Enable_the_search_head...

splunkreal
Motivator

Dear Somesh,

finally I've added search peers (indexers of the cluster) in distributed search of the new sh and it looks good!

I don't want any sync or replication of clustered search heads.

Thanks a lot.

* If this helps, please upvote or accept solution 🙂 *
0 Karma

splunkreal
Motivator

Hello, we have an app (app_authentication) used to deploy authorize.conf and authentication.conf on our shcluster. Does it mean that I only need to disable deployment of this app on the new search head and configure users/roles locally? Thanks a lot.

* If this helps, please upvote or accept solution 🙂 *
0 Karma

somesoni2
Revered Legend

You would've to create a copy of that app, make required permissions changes in the app and deploy updated app to your Standalone SH.

0 Karma

splunkreal
Motivator

Can't we just add search peers (clustered indexers) in "Settings / distributed search / search peers" from the new sh?

The aim is to avoid that that additionnel search head becomes part of the cluster.

Thanks for your help.

* If this helps, please upvote or accept solution 🙂 *
0 Karma

somesoni2
Revered Legend

A search in an indexer cluster will still be behaving a regular SH only. The benefits of configuring search peers by adding SH to cluster is that you don't have to make changes in SH if there is change in the Indexer cluster (you add or remove search peers from cluster). See this for comparison of both methods

http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Configurethesearchhead#Search_heads_runnin...

0 Karma

splunkreal
Motivator

The aim for that standalone search head is to have different permissions for existing clustered indexes. Is it possible with your solution?
Thanks.

* If this helps, please upvote or accept solution 🙂 *
0 Karma

somesoni2
Revered Legend

The permissions are handled at role level on Search Head, so you should be able to manage index level permission per your need.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...