Understanding search head clusters
A Splunk search head cluster is a set of three or more Splunk search heads working together as one to improve search capacity and increase availability against single server failures. The exact number of search heads in the search head cluster is determined by the number of concurrent users, the number of searches run on the search heads, and the level of availability required. With a traditional unclustered search head arrangement, a failure of one search head results in the loss of search artifacts or search results, configurations, apps/add-ons, and search jobs. Configuring search heads into a search head cluster can improve availability and scalability as the number of users and searches increases.
Figure 9.1 illustrates a simple three-node search head cluster:
Figure 9.1 – A search head cluster
There are three main components of a search head cluster:
- The search head cluster members include the...