Hello, We have migrated our standalone installation of Splunk Enterprise to a "Small enterprise distributed deployment". This is a really small distributed deployment because the load is essentially on indexing capacity, even though it's less than 100Go daily (our licence allows 80Go) and search load is really low. So we have : - 1 Search Head - 2 indexers (no cluster) The search head also acts as license master and deployment server (just HEC configs and indexes replication to indexers). Now the question is : Is it possible to install Monitoring Console on the Search Head node ? We've well seen the recommandation here, and especially : "When you set up the monitoring console in distributed mode, it creates one search group for each server role, identified cluster, or custom group. Unless you use a "splunk_server_group" or the "splunk_server" option, only search peers that are members of the indexer group are searched by default. Because all searches that run on the monitoring console instance follow this behavior, non-monitoring console searches might have incomplete results." I'm not sure I really understand this, but as we only have 2 indexers and since they are the nodes that we want to put in the indexer group on the MC side, could it really leads to incomplete searchs ? It seems that this is the same advice given on dashboard, via the MC general setup page when trying to activate in distributed mode : "Do not configure the DMC in distributed mode if this is a production search head. Doing so can change the behavior of all searches on this instance. This is dangerous and unsupported." As already said, load consideration is secondary because we do not have a heavy searching activity. Thanks a lot.
... View more