<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help in Replication. in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Need-help-in-Replication/m-p/476800#M16591</link>
    <description>&lt;P&gt;There is no such thing as a &lt;CODE&gt;Master Indexer&lt;/CODE&gt;. You should have a created an &lt;CODE&gt;app&lt;/CODE&gt; inside of &lt;CODE&gt;master-apps&lt;/CODE&gt; on the &lt;CODE&gt;Cluster Master&lt;/CODE&gt; that contains an &lt;CODE&gt;indexes.conf&lt;/CODE&gt; file.  DO NOT create any splunk configuration files for this directly on any indexers.  Then push out the &lt;CODE&gt;indexes.conf&lt;/CODE&gt; app (which has the file) using the &lt;CODE&gt;cluster&lt;/CODE&gt; commands on the &lt;CODE&gt;Cluster Master&lt;/CODE&gt;.  This will cause a rolling restart on the Indexers once they receive the new configurations, after which you will be able to send data to the new index on the indexers.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Nov 2019 15:01:14 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-11-07T15:01:14Z</dc:date>
    <item>
      <title>Need help in Replication.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Need-help-in-Replication/m-p/476797#M16588</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;

&lt;P&gt;I have created a Indexer cluster. In my master indexer I created one Index and added some data (/etc/master-app/_cluster/local). and pushed the index to all the peers. Index is replicated in all the indexer But data is showing in only master index. Now I want to add some data to all my indexer. What should I do?&lt;/P&gt;

&lt;P&gt;Thanks &lt;BR /&gt;
Vikash Gupta&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 08:03:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Need-help-in-Replication/m-p/476797#M16588</guid>
      <dc:creator>vikcee</dc:creator>
      <dc:date>2019-11-07T08:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in Replication.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Need-help-in-Replication/m-p/476798#M16589</link>
      <description>&lt;P&gt;Could you share the indexes.conf? Also, on which Splunk instance wrote your inputs.conf?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 08:14:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Need-help-in-Replication/m-p/476798#M16589</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2019-11-07T08:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in Replication.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Need-help-in-Replication/m-p/476799#M16590</link>
      <description>&lt;P&gt;We may have a terminology problem.  There is no such thing as a "master indexer".  The instance in charge of an indexer cluster is the "Master Node" or "Cluster Master".  A clustered indexer cannot serve as the Master.&lt;BR /&gt;
Defining an index on the Master Node (MN) and pushing the configuration to the peers will define that index on all indexers.&lt;BR /&gt;
All of your Splunk instances should be forwarding their output to the indexers.  Not only does that make all Splunk logs searchable, but it also means data added on the MN or a Search Head will be sent to the indexers and replicated properly.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 13:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Need-help-in-Replication/m-p/476799#M16590</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-11-07T13:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in Replication.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Need-help-in-Replication/m-p/476800#M16591</link>
      <description>&lt;P&gt;There is no such thing as a &lt;CODE&gt;Master Indexer&lt;/CODE&gt;. You should have a created an &lt;CODE&gt;app&lt;/CODE&gt; inside of &lt;CODE&gt;master-apps&lt;/CODE&gt; on the &lt;CODE&gt;Cluster Master&lt;/CODE&gt; that contains an &lt;CODE&gt;indexes.conf&lt;/CODE&gt; file.  DO NOT create any splunk configuration files for this directly on any indexers.  Then push out the &lt;CODE&gt;indexes.conf&lt;/CODE&gt; app (which has the file) using the &lt;CODE&gt;cluster&lt;/CODE&gt; commands on the &lt;CODE&gt;Cluster Master&lt;/CODE&gt;.  This will cause a rolling restart on the Indexers once they receive the new configurations, after which you will be able to send data to the new index on the indexers.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 15:01:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Need-help-in-Replication/m-p/476800#M16591</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-07T15:01:14Z</dc:date>
    </item>
  </channel>
</rss>

