Splunk Enterprise Security

Having a separate ES search head from a general search head

hopnscotch
Path Finder

Is it possible/ok to have 1 search head running ES and one without? We will have a large number of overall users but only 7-8 using the ES app. I'm trying to avoid search head pooling if possible.

Any thoughts around this are welcome. Thanks

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

it means separate from other search heads. This can be confusing in a small instance where you don't need to distinguish between search heads and indexers, but once you go to "pool of indexers with search heads floating on top" it starts getting clearer.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

It's more the other way around -- a separate search head is the recommendation / requirement, but it's possible to run other apps on there as well.

0 Karma

hopnscotch
Path Finder

I did read that a separate SH is required. The way that is worded is confusing those.. separate from what? indexers or other search heads?

I will have a separate index cluster. My question is if there are any issues with having a search head that is NOT running ES along side one that is searching the same indexers. I guess the only other thing that ties them together is the license so just wondering if there are any issues with this scenario.

Thanks

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...