Configure the search head with server.conf
Prerequisites
Before reading this topic, see Configure the indexer cluster with server.conf. It discusses configuration issues that are common to all cluster node types.
Enable a search head
The following example shows the basic settings that you must configure when enabling a search head node. The configuration attributes shown here correspond to fields on the Enable clustering page of Splunk Web.
[clustering] manager_uri = https://10.152.31.202:8089 mode = searchhead pass4SymmKey = whatever
This example specifies that:
- the search head's cluster manager node resides at
10.152.31.202:8089
. - the instance is a cluster search head.
- the security key is "whatever".
Edit the search head settings
You can change these settings later, if necessary. For example, to change the cluster's security key, you change the pass4SymmKey
value on each node.
You can also configure the search head to search across multiple indexer clusters or across clustered and non-clustered search peers. See:
Configure the search head with the dashboard | Configure the search head with the CLI |
This documentation applies to the following versions of Splunk® Enterprise: 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.1.7, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.3.0, 9.3.1, 9.3.2
Feedback submitted, thanks!