<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to monitor search head cluster from a monitoring console? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/546412#M18715</link>
    <description>&lt;P&gt;Mr. Woodcock, I have 2 MC in distributed mode - only 1 showing peers. 2 MC in standalone mode no peers defined. It is something I inherited. Does this look like over doing it? Too much resources used for same reasons? Please advise.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Apr 2021 18:11:40 GMT</pubDate>
    <dc:creator>SamHTexas</dc:creator>
    <dc:date>2021-04-01T18:11:40Z</dc:date>
    <item>
      <title>How to monitor search head cluster from a monitoring console?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/467740#M16351</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I have a clustered environment where I have 1 indexer master/license master, 1 search head deployer, 3 search heads in search head cluster and 2 indexers in an indexer cluster. &lt;BR /&gt;
I have set up a monitoring console on the license master and changed it to distributed mode. &lt;BR /&gt;
I can see my indexers there, but I don't see my search heads. &lt;/P&gt;

&lt;P&gt;I followed the documentation and went to Settings -&amp;gt; Distributed Search -&amp;gt; Search Peers and tried doing add new search peer and provided my search head URL&lt;BR /&gt;
&lt;A href="https://xxxxx1:8089"&gt;https://xxxxx1:8089&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I added all my search heads, but when I add it, I see that the cluster label shows as indexercluster1 - that's my indexer cluster label. &lt;/P&gt;

&lt;P&gt;Why is my search head showing as an indexer cluster member when I add it here?&lt;BR /&gt;
Also, the replication status gets set to Initial when I add it and then changes to Successful. &lt;BR /&gt;
What is it replicating? &lt;/P&gt;

&lt;P&gt;And even after this, when I check the topology under search heads it's not showing any of the above machines that I added. &lt;BR /&gt;
I presume it's considering them as indexers as its showing the indexer cluster label. &lt;/P&gt;

&lt;P&gt;How do I fix this so that I can monitor my search heads and the search head deployer too through this monitoring console?&lt;BR /&gt;
Any help is greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 20:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/467740#M16351</guid>
      <dc:creator>vinaypradhan</dc:creator>
      <dc:date>2019-10-29T20:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor search head cluster from a monitoring console?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/467741#M16352</link>
      <description>&lt;P&gt;you have to edit the server roles at MC and setup the search head hosts to search head.&lt;BR /&gt;
Go to Management Console/Settings/Forwarders/General Setup/Actions/Edit and change to "search head" role&lt;/P&gt;

&lt;P&gt;As you are working on an indexer cluster environment, the data is being replicated to the entire indexer cluster, so if one of indexers cluster peers went down, you are still able to search the data.&lt;BR /&gt;
I recommend for you to read this document to understand how indexer replication works&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.2/Indexer/Aboutclusters"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.2/Indexer/Aboutclusters&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 21:55:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/467741#M16352</guid>
      <dc:creator>ivanreis</dc:creator>
      <dc:date>2019-10-29T21:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor search head cluster from a monitoring console?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/467742#M16353</link>
      <description>&lt;P&gt;hi IvanReis, thanks for your reply. I do understand indexer cluster replication. but when i go to Settings -&amp;gt; Distributed Search -&amp;gt; Search Peers and add my search head there, it shows my indexer cluster label against it and shows replication is Initial and after some time successful - i dont want any of my indexed data to be replicated on my search heads. the sole reason i am adding my search head here, is to be able to get my search head in the monitoring console to show up as a search head, but even after adding it here, it doesnt show up in my monitoring console as a search head&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 14:52:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/467742#M16353</guid>
      <dc:creator>vinaypradhan</dc:creator>
      <dc:date>2019-10-30T14:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor search head cluster from a monitoring console?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/467743#M16354</link>
      <description>&lt;P&gt;Per my understanding, it seems your search head is setup as indexer at management console. You have to change the search head server role to only search head. If the server role is not properly defined at MC, the server will be added to other role, in some cases you have to manually changed it.&lt;/P&gt;

&lt;P&gt;Management Console/Settings/Forwarders/General Setup/Actions/Edit and change to "search head" role&lt;/P&gt;

&lt;P&gt;After run this configuration, save it and restart the MC and check if the server is setup to "search head" role.&lt;/P&gt;

&lt;P&gt;It is considered a best practice to forward all search head internal data to the search peer (indexer) layer. Check the document below&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.2/DistSearch/Forwardsearchheaddata"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.2/DistSearch/Forwardsearchheaddata&lt;/A&gt;&lt;BR /&gt;
Make sure your search head clusters is f&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 23:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/467743#M16354</guid>
      <dc:creator>ivanreis</dc:creator>
      <dc:date>2019-10-30T23:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor search head cluster from a monitoring console?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/467744#M16355</link>
      <description>&lt;P&gt;Do/check these on MC:&lt;BR /&gt;
Go to &lt;CODE&gt;Search peers&lt;/CODE&gt; and ensure that ALL Splunk infrastructure nodes are peers.  When you peer the CM, the Indexers should peer in, but if not, add those, too.&lt;BR /&gt;
Go to &lt;CODE&gt;Monitoring Console&lt;/CODE&gt; -&amp;gt; &lt;CODE&gt;Setup&lt;/CODE&gt; -&amp;gt; &lt;CODE&gt;General Setup&lt;/CODE&gt; and select &lt;CODE&gt;Distributed Mode&lt;/CODE&gt; then edit each peer to manually assign the correct roles.  Click &lt;CODE&gt;Apply&lt;/CODE&gt; and then PROFIT!!!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 23:43:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/467744#M16355</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-10-30T23:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor search head cluster from a monitoring console?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/467745#M16356</link>
      <description>&lt;P&gt;thank you all, i was able to follow woodcock's suggestion and get my search heads in the monitoring console. &lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 14:15:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/467745#M16356</guid>
      <dc:creator>vinaypradhan</dc:creator>
      <dc:date>2019-11-05T14:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor search head cluster from a monitoring console?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/546412#M18715</link>
      <description>&lt;P&gt;Mr. Woodcock, I have 2 MC in distributed mode - only 1 showing peers. 2 MC in standalone mode no peers defined. It is something I inherited. Does this look like over doing it? Too much resources used for same reasons? Please advise.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 18:11:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-monitor-search-head-cluster-from-a-monitoring-console/m-p/546412#M18715</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-04-01T18:11:40Z</dc:date>
    </item>
  </channel>
</rss>

