Getting Data In

Single Indexer with 2 different Search Heads?

Strype
Path Finder

Although I personally wouldn't want to set it up this way...

Is it possible to have one indexer that works for 2 separate search heads with 2 separate knowledge bundles? Wouldn't that cause a problem?

0 Karma

daniel_splunk
Splunk Employee
Splunk Employee

If you want both search head to use the common set of knowledge bundle, you need to configure Search head pooling.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

It is possible! However, any extractions that you want from one to the other need manually transferred. The data would be indexed in exactly the same way, but any Apps or search time modifications would be different.

Strype
Path Finder

Thanks so much!

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...