search head

noun

In a distributed search environment, a Splunk instance that handles search management functions, directing search requests to a set of search peers and then merging the results back to the user.

A Splunk instance can function as both a search head and a search peer. If it does only searching (and not any indexing), it is usually referred to as a dedicated search head.

Search heads are also required components of clusters.


Related terms

For more information

In the Distributed Deployment Manual:

In the Managing Indexers and Clusters manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time