<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Add second index cluster to search head in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Add-second-index-cluster-to-search-head/m-p/543312#M18633</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Ill try and keep it short and to the point.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a standalone search head that is currently connected to an index cluster with 4 peers. We would now like to connect a second 3 peer index cluster that is hosted in AWS.&lt;/P&gt;&lt;P&gt;When I add the AWS cluster master to the search head via Settings -&amp;gt; Indexer Clustering it actually fails to connect due to the below error:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Master has multisite enabled but the search head is missing the 'multisite' attribute'&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;but if I configure in the server.conf file and reboot, the AWS cluster master connects fine but the 3 peers do not appear as per below screenshot and I am not able to search the indexes.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Peers.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13258i11ADCFE5DD9CE457/image-size/large?v=v2&amp;amp;px=999" role="button" title="Peers.PNG" alt="Peers.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If I manually add the index peers under Settings -&amp;gt; Distributed Search -&amp;gt; New Search Peer, the peers add fine and I am able to search indexes in AWS as required.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need the peers to be discovered automatically by the search head via the cluster master as the AWS indexers are rebuilt on a regular basis.&lt;/P&gt;&lt;P&gt;Below is the server.conf on our search head&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="server.conf.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13259i498648CF2903DF29/image-size/large?v=v2&amp;amp;px=999" role="button" title="server.conf.PNG" alt="server.conf.PNG" /&gt;&lt;/span&gt;and I have been informed that autodiscovery is enabled on the AWS Cluster master.&lt;/P&gt;&lt;P&gt;I have logged a case with Splunk but thought I would try here as well.&lt;/P&gt;&lt;P&gt;Any information would be appreciated&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trev&lt;/P&gt;</description>
    <pubDate>Thu, 11 Mar 2021 06:38:19 GMT</pubDate>
    <dc:creator>trevor_dunstan8</dc:creator>
    <dc:date>2021-03-11T06:38:19Z</dc:date>
    <item>
      <title>Add second index cluster to search head</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Add-second-index-cluster-to-search-head/m-p/543312#M18633</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Ill try and keep it short and to the point.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a standalone search head that is currently connected to an index cluster with 4 peers. We would now like to connect a second 3 peer index cluster that is hosted in AWS.&lt;/P&gt;&lt;P&gt;When I add the AWS cluster master to the search head via Settings -&amp;gt; Indexer Clustering it actually fails to connect due to the below error:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Master has multisite enabled but the search head is missing the 'multisite' attribute'&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;but if I configure in the server.conf file and reboot, the AWS cluster master connects fine but the 3 peers do not appear as per below screenshot and I am not able to search the indexes.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Peers.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13258i11ADCFE5DD9CE457/image-size/large?v=v2&amp;amp;px=999" role="button" title="Peers.PNG" alt="Peers.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If I manually add the index peers under Settings -&amp;gt; Distributed Search -&amp;gt; New Search Peer, the peers add fine and I am able to search indexes in AWS as required.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need the peers to be discovered automatically by the search head via the cluster master as the AWS indexers are rebuilt on a regular basis.&lt;/P&gt;&lt;P&gt;Below is the server.conf on our search head&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="server.conf.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13259i498648CF2903DF29/image-size/large?v=v2&amp;amp;px=999" role="button" title="server.conf.PNG" alt="server.conf.PNG" /&gt;&lt;/span&gt;and I have been informed that autodiscovery is enabled on the AWS Cluster master.&lt;/P&gt;&lt;P&gt;I have logged a case with Splunk but thought I would try here as well.&lt;/P&gt;&lt;P&gt;Any information would be appreciated&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trev&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 06:38:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Add-second-index-cluster-to-search-head/m-p/543312#M18633</guid>
      <dc:creator>trevor_dunstan8</dc:creator>
      <dc:date>2021-03-11T06:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: Add second index cluster to search head</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Add-second-index-cluster-to-search-head/m-p/543314#M18634</link>
      <description>&lt;P&gt;I should have also mentioned that FW rules appear to be in place as I am able to SSH directly to the AWS cluster master and AWS indexers from our search head over port 8089&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 06:40:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Add-second-index-cluster-to-search-head/m-p/543314#M18634</guid>
      <dc:creator>trevor_dunstan8</dc:creator>
      <dc:date>2021-03-11T06:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Add second index cluster to search head</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Add-second-index-cluster-to-search-head/m-p/543326#M18636</link>
      <description>Hi&lt;BR /&gt;Otherwise it seems to be correct, but can you add multisite = false to onperm-master stanza?&lt;BR /&gt;r. Ismo</description>
      <pubDate>Thu, 11 Mar 2021 08:04:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Add-second-index-cluster-to-search-head/m-p/543326#M18636</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-03-11T08:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Add second index cluster to search head</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Add-second-index-cluster-to-search-head/m-p/544098#M18658</link>
      <description>&lt;P&gt;Issue turned out to be a DNS issue and our search head was not able to resolve DNS names for the indexers in AWS. As an interim solution we have updated the hosts file on the search head with the AWS pool of IP addresses and hostnames for the AWS indexers. Not elegant by any means but is temporary until DNS forwarders can be set up.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 02:37:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Add-second-index-cluster-to-search-head/m-p/544098#M18658</guid>
      <dc:creator>trevor_dunstan8</dc:creator>
      <dc:date>2021-03-17T02:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Add second index cluster to search head</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Add-second-index-cluster-to-search-head/m-p/544152#M18659</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;we are using DNS names on all configurations and updated those when creating new server / after termination , when server brings up with different IP. This has done on our ansible scripts by calling r53 services. Is this suitable option for you?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 10:44:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Add-second-index-cluster-to-search-head/m-p/544152#M18659</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-03-17T10:44:47Z</dc:date>
    </item>
  </channel>
</rss>

