Splunk Enterprise Security

Search Head Pooling v. Search Head Clustering

hberkis
New Member

If i am running Splunnk 6.2.x and ES 3.x using search head pooling, and I upgrade to Splunk 6.3.1 and ES 4.0.1 using search head pooling;
* is this supported
* will this cause problems? performance issues, etc.

0 Karma

hberkis
New Member

Can anyone guess what the impact would be if this were implemented?

0 Karma

somesoni2
Revered Legend

Are you using native Splunk SH pooling OR custom?

0 Karma

hberkis
New Member

We are using native sh pooling.

0 Karma

somesoni2
Revered Legend

Well, native SH Pooling is not supported by ES 4.0.1, as mentioned by @schose. But SH Cluster is supported (on Linux Platform), so consider migrating to the same.

0 Karma

schose
Builder

ES 4.x does not support searchhead pooling
"Splunk Enterprise Security does not support search head pooling."

http://docs.splunk.com/Documentation/ES/4.0.1/Install/DeploymentPlanning

Regards,

Andreas

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...