<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best practice: add indexers as search peers for the heavy forwarders ? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554543#M18871</link>
    <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;said if you want to select index from list then you must add those to HF. As you have configured index forwarding (at least you should) there is no real harm to copy same indexes.conf from IDX to HF. Another option is use directly those config files to add hec information or use cli for that.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jun 2021 20:29:51 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2021-06-04T20:29:51Z</dc:date>
    <item>
      <title>Best practice: add indexers as search peers for the heavy forwarders ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554448#M18863</link>
      <description>&lt;P&gt;When configuring data inputs on a heavy forwarder via the GUI (HEC, for instance), the destination index is requested but it has to be selected from a &lt;STRONG&gt;list&lt;/STRONG&gt; which obviously is not coming from our indexers because it contains only default indexes.&lt;/P&gt;&lt;P&gt;Should we add the indexers as search peers for this list to be correctly populated ? Is it best practice or is there any drawback doing so ? Also do you add the heavy forwarders as search heads in the monitoring console ?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 09:19:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554448#M18863</guid>
      <dc:creator>yoho</dc:creator>
      <dc:date>2021-06-04T09:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice: add indexers as search peers for the heavy forwarders ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554450#M18864</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/17800"&gt;@yoho&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you need to add Indexes to the HF only if you want to sore a local copy of data otherwise you don't need it.&lt;/P&gt;&lt;P&gt;Obviously you have to know the names of the indexes to send data that are on Indexers because you don't see them in HFs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 09:24:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554450#M18864</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-04T09:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice: add indexers as search peers for the heavy forwarders ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554456#M18865</link>
      <description>&lt;P&gt;Yes, you don't see the indexes when you go to Settings &amp;gt; Data Inputs (in the GUI) and configure any of the data inputs on this page (HTTP event collector, for instance).&lt;/P&gt;&lt;P&gt;My question was actually if there was a possibility to make them visible in the list (because contrary to the sourcetype, you can not type anything, you have to select from a fixed list).&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 09:53:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554456#M18865</guid>
      <dc:creator>yoho</dc:creator>
      <dc:date>2021-06-04T09:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice: add indexers as search peers for the heavy forwarders ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554458#M18866</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/17800"&gt;@yoho&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the only way to see in the list is to create indexes on HFs but it's unuseful!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 09:55:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554458#M18866</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-04T09:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice: add indexers as search peers for the heavy forwarders ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554543#M18871</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;said if you want to select index from list then you must add those to HF. As you have configured index forwarding (at least you should) there is no real harm to copy same indexes.conf from IDX to HF. Another option is use directly those config files to add hec information or use cli for that.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 20:29:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554543#M18871</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-06-04T20:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice: add indexers as search peers for the heavy forwarders ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554551#M18872</link>
      <description>&lt;P&gt;Ok, thanks for the replies. I find it stupid the choice of index is not:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Via a list populated by making a REST call to your search peers / indexers&lt;/LI&gt;&lt;LI&gt;OR available for you to type in a free-form text field, like for the sourcetype&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 04 Jun 2021 21:44:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554551#M18872</guid>
      <dc:creator>yoho</dc:creator>
      <dc:date>2021-06-04T21:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice: add indexers as search peers for the heavy forwarders ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554850#M18879</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/17800"&gt;@yoho&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 08:06:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Best-practice-add-indexers-as-search-peers-for-the-heavy/m-p/554850#M18879</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-08T08:06:35Z</dc:date>
    </item>
  </channel>
</rss>

