Splunk Search

NAS in search head

Splunk_U
Path Finder

I have two search heads. I want that if a user logged in to SRCH1 and saved a search and logged off and then looged in to SRCH2 then he/she should get the saved search. For that I want to configure a NAS where all the user data will be stored irrespective of the search heads. Is it possible? If yes then how can I configure that?

Tags (3)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

That sounds a lot like search head pooling: http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuresearchheadpooling

Edit: Too slow...

0 Karma

kristian_kolb
Ultra Champion

I think that what you are looking for is a functionality called 'Search Head Pooling'.

http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Configuresearchheadpooling

/k

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...