search head

noun

In a distributed search environment, a Splunk instance that directs search requests to one or more search peers.

A Splunk instance can function as both a search head and a search peer. If it does only searching (and not any indexing), it is usually referred to as a dedicated search head.


Related terms

For more information

In the Installation Manual:

In the Distributed Deployment Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time