Search Head Clustering (SHC) groups multiple search heads that share configurations, saved searches, dashboards, and user data. This provides high availability and load balancing for the search tier.
SHC uses a Captain — a dynamically elected leader that coordinates replication and artifact synchronization. If the Captain fails, a new one is elected automatically.
A Deployer pushes app and configuration updates to all SHC members. Unlike regular deployment server, the Deployer uses the shcluster/apps/ directory.
./splunk show shcluster-status
Captain: sh1.company.com
Members: 3
Dynamic Captain: true