先看一下架构:
1: deoply a new search head server.
docker run --network skynet --name sh02 --hostname sh02 -p 8006:8000 -e "SPLUNK_PASSWORD=sheng2020" -e "SPLUNK_START_ARGS=--accept-license" -it splunk/splunk:latest
2: it is easier to enable it in web:
Setting --> index clustering --> enable -> search head node
3: check the status is fine: