<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Distributed search from a SH Cluster to multiple Indexer Clusters in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-from-a-SH-Cluster-to-multiple-Indexer/m-p/557902#M18957</link>
    <description>&lt;P&gt;Hey Splunkers!&lt;/P&gt;&lt;P&gt;We have multiple IDX/SH clusters that are peered based on regulatory/compliance/operational reasons. We have a specific SHC that we would like to de-peer from an older IDX cluster. Indexes are reused and migrated across different IDX clusters frequently.&lt;/P&gt;&lt;P&gt;What is the fastest and most accurate way to see what data is being fetched from the IDX clusters by a SHC?&lt;/P&gt;&lt;P&gt;Thanks in Advance!&lt;/P&gt;</description>
    <pubDate>Wed, 30 Jun 2021 19:33:44 GMT</pubDate>
    <dc:creator>Aatom</dc:creator>
    <dc:date>2021-06-30T19:33:44Z</dc:date>
    <item>
      <title>Distributed search from a SH Cluster to multiple Indexer Clusters</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-from-a-SH-Cluster-to-multiple-Indexer/m-p/557902#M18957</link>
      <description>&lt;P&gt;Hey Splunkers!&lt;/P&gt;&lt;P&gt;We have multiple IDX/SH clusters that are peered based on regulatory/compliance/operational reasons. We have a specific SHC that we would like to de-peer from an older IDX cluster. Indexes are reused and migrated across different IDX clusters frequently.&lt;/P&gt;&lt;P&gt;What is the fastest and most accurate way to see what data is being fetched from the IDX clusters by a SHC?&lt;/P&gt;&lt;P&gt;Thanks in Advance!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 19:33:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-from-a-SH-Cluster-to-multiple-Indexer/m-p/557902#M18957</guid>
      <dc:creator>Aatom</dc:creator>
      <dc:date>2021-06-30T19:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed search from a SH Cluster to multiple Indexer Clusters</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-from-a-SH-Cluster-to-multiple-Indexer/m-p/557904#M18958</link>
      <description>&lt;P&gt;Hi.&amp;nbsp; Just by searching answers I found these two: You can list the indexers your heads are talking to with&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest /services/server/info | table splunk_server&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;You can list all the indexes with tstats (you would need a large window of time, possibly)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats count WHERE index=* by index | table index&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 19:52:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-from-a-SH-Cluster-to-multiple-Indexer/m-p/557904#M18958</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2021-06-30T19:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed search from a SH Cluster to multiple Indexer Clusters</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-from-a-SH-Cluster-to-multiple-Indexer/m-p/557908#M18960</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/155648"&gt;@burwell&lt;/a&gt;&amp;nbsp;, we know we are currently peered, and am familiar with both the options you provided, but I am trying to go deeper. What I would like to find is an output that shows actual results (bytes, buckets, meta, etc) returned from the Indexer Cluster we want to de-peer from, based on the outgoing queries from the SHC.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 20:09:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-from-a-SH-Cluster-to-multiple-Indexer/m-p/557908#M18960</guid>
      <dc:creator>Aatom</dc:creator>
      <dc:date>2021-06-30T20:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed search from a SH Cluster to multiple Indexer Clusters</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-from-a-SH-Cluster-to-multiple-Indexer/m-p/557928#M18961</link>
      <description>&lt;P&gt;You want to know when your users are querying the indexers you want to de peer from?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 23:30:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-from-a-SH-Cluster-to-multiple-Indexer/m-p/557928#M18961</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2021-06-30T23:30:43Z</dc:date>
    </item>
  </channel>
</rss>

