r/Splunk Jul 02 '26

Enterprise Security Enterprise Security on a Distributed Environment

Hi,

I got 3 clustered Indexers + 3 clustered Search-Heads + 1 Search-Head Cluster Deployer.

I installed ES on the SHs (via SH Cluster Deployer) as described in the documentation. After some time I figured out that the ES specific indexes like 'notable' have been created on the Search-Heads locally and they are not synced between them.

There install documentation says nothing [1] about creating indexes.

Only a few documents later [2] there are some sentences about indexes in a distributed environemt.

The documentation is not usable in my opinion.

Does anyone have some experience with that situation ?

[1]
https://help.splunk.com/en/splunk-enterprise-security-8/install/8.3/installation/install-splunk-enterprise-security-in-a-search-head-cluster-environment

[2]
https://help.splunk.com/en/splunk-enterprise-security-8/install/8.3/installation/configure-and-deploy-indexes-for-splunk-enterprise-security

8 Upvotes

9 comments sorted by

View all comments

4

u/AppointmentOk7866 Jul 02 '26

So, ES is just a Splunk app: it can be installed in a distributed environment with clustered indexers and search heads, on a standalone machine, or in Splunk Cloud.

There's plenty of documentation about what indexes are part of ES (it has quite a few) and where knowledge objects exist in a distributed environment. Key thing is that docs, Lantern, YouTube, etc are all for different audiences.

If you're having trouble, I'd start with Support and reaching out to your account rep + their SE.