Splunk Admin Roadmap - Day 4 - How to setup Search Head

Опубликовано: 02 Июль 2026
на канале: Soft Mania
139
4

The Search Head is where the magic happens. We’ll walk through the setup so you can start visualizing data and running powerful queries.

Splunk Admin Roadmap – Day 4 | Search Head Setup

In this video, we explain how to set up a Splunk Search Head from scratch.
This video is part of the Splunk Admin Roadmap – Day 4.

We begin with pre-installation checks, then install Splunk using CLI commands, and finally complete post-installation checks.
By the end of this video, the Search Head will be connected to the Indexer and ready to use.

Topics Covered:
Pre-Installation Checks
We verify the basic OS requirements:
OS version (Red Hat Linux 9.4)
Disk space and partition
CPU and memory
Splunk user and group
/opt/splunk directory and ownership
Port availability using netstat and ss
THP disabled status
Ulimit values
NTP time synchronization

Search Head Installation
Switch to Splunk user
Download Splunk Enterprise using CLI
Extract the package
Start Splunk and accept the license
Create admin username and password
Access Splunk UI on port 8000

UI Configuration:
Verify server name and host name
Create a global banner for Search Head
Use banner colors to identify Search Head and Indexer
Post-Installation Checks
Verify Splunk starts at boot time
Check server name and host name
Verify default ports:
Web: 8000
Management: 8089
KV Store: 8191
App Server: 8065

Connect Search Head to Indexer
Create service admin user on Indexer
Configure Distributed Search
Add Indexer as a Search Peer
Validate connection and replication

Validation
Run test searches
Search _internal index
Confirm logs from both Search Head and Indexer

This confirms the Search Head is successfully connected to the Indexer and ready for distributed search
...................................................................................................................

Want to become expert in Splunk SIEM ???
Here is the 4 stage roadmap (With Live Projects) to gain real-time experience

Stage-1: Learn IT basics & Security Essentials
To Learn those topics, Watch below videos for free
1)    • Day-1 | Batch-1 | CyberSecurity - Introduc...  
2) https://www.youtube.com/live/hVCKZKwB...
3) https://www.youtube.com/live/sUU3wDGj...
4) https://www.youtube.com/live/knrtIdqK...

Stage-2: Learn Splunk basics
To Learn those topics, Register for this beginner bootcamp for free
Link: https://splunk.softmania.in/course/fr...

Stage-3: Do 10+ Live Splunk Projects
To do these projects, enroll for this Intermediate bootcamp
Link: https://splunk.softmania.in/session/s...

Stage-4: Learn Splunk Architect topics
To do these projects, enroll for this Expert bootcamp
Link: https://splunk.softmania.in/course/so...
Need help in deciding?? - DM us on WhatsApp - http://wa.me/918317349618