Deployment Architecture

Multiple search heads, one indexer

smileyge
Path Finder

Is it possible to set up several search heads to search the same index if, say, I wanted a particular search head to only search an index or two, and leave the other one searching all indexes. I would not add another indexer.

Tags (2)

lpolo
Motivator

Yes. It is possible to define the specific search peers you need in each search head.
More information:

http://docs.splunk.com/Documentation/Splunk/6.1.1/DistSearch/Configuredistributedsearch

Thanks,
Lp

lpolo
Motivator

Each indexer and search head has its own license configuration. If you are using a license server all the indexers and search heads has to point to the same license server. If you have 2 license servers, you could have a set of indexers and search heads pointing to one license server and the other set pointing to the other license server.
More information about license server:

http://docs.splunk.com/Documentation/Splunk/6.1.1/Admin/HowSplunklicensingworks

0 Karma

smileyge
Path Finder

I have seen that as well as the docs on search pools, so thanks for helping me understand which one I want. When adding a peer, what license file is used and does replicating the data consume license volume?

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...