Splunk Search

Splunk realtime searches high availible

nebel
Communicator

Hi there,

I am having a searchhead which runs a lot RT-Searches with a eMail alerting.
Now I want to have a kind of HA, means if my searchhead goes down and cannot search anymore, is there a way that another searchhead apply those searches? Or can I use two searchheads? But if something happend I get an eMail alert twice...

What can I do in this case?

Thanks a lot

Cheers

Tags (2)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee
0 Karma

sdaniels
Splunk Employee
Splunk Employee

You may want to take a look at Search Head pooling.

http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuresearchheadpooling

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...