Hi there,
I am having a searchhead which runs a lot RT-Searches with a eMail alerting.
Now I want to have a kind of HA, means if my searchhead goes down and cannot search anymore, is there a way that another searchhead apply those searches? Or can I use two searchheads? But if something happend I get an eMail alert twice...
What can I do in this case?
Thanks a lot
Cheers
You may want to take a look at Search Head pooling.
http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuresearchheadpooling
You may want to take a look at Search Head pooling.
http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuresearchheadpooling