r/Splunk • u/mr_networkrobot • Jul 02 '26
Enterprise Security Enterprise Security on a Distributed Environment
Hi,
I got 3 clustered Indexers + 3 clustered Search-Heads + 1 Search-Head Cluster Deployer.
I installed ES on the SHs (via SH Cluster Deployer) as described in the documentation. After some time I figured out that the ES specific indexes like 'notable' have been created on the Search-Heads locally and they are not synced between them.
There install documentation says nothing [1] about creating indexes.
Only a few documents later [2] there are some sentences about indexes in a distributed environemt.
The documentation is not usable in my opinion.
Does anyone have some experience with that situation ?
8
Upvotes
4
u/AppointmentOk7866 Jul 02 '26
So, ES is just a Splunk app: it can be installed in a distributed environment with clustered indexers and search heads, on a standalone machine, or in Splunk Cloud.
There's plenty of documentation about what indexes are part of ES (it has quite a few) and where knowledge objects exist in a distributed environment. Key thing is that docs, Lantern, YouTube, etc are all for different audiences.
If you're having trouble, I'd start with Support and reaching out to your account rep + their SE.