Splunk Enterprise Security

Search Head Pooling v. Search Head Clustering

hberkis
New Member

If i am running Splunnk 6.2.x and ES 3.x using search head pooling, and I upgrade to Splunk 6.3.1 and ES 4.0.1 using search head pooling;
* is this supported
* will this cause problems? performance issues, etc.

0 Karma

hberkis
New Member

Can anyone guess what the impact would be if this were implemented?

0 Karma

somesoni2
Revered Legend

Are you using native Splunk SH pooling OR custom?

0 Karma

hberkis
New Member

We are using native sh pooling.

0 Karma

somesoni2
Revered Legend

Well, native SH Pooling is not supported by ES 4.0.1, as mentioned by @schose. But SH Cluster is supported (on Linux Platform), so consider migrating to the same.

0 Karma

schose
Builder

ES 4.x does not support searchhead pooling
"Splunk Enterprise Security does not support search head pooling."

http://docs.splunk.com/Documentation/ES/4.0.1/Install/DeploymentPlanning

Regards,

Andreas

Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...