<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do we need to Forward to all Indexers in a two site Index Cluster? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/625980#M26527</link>
    <description>&lt;P&gt;OK. But this is about searching, not about forwarding events to indexers and you asked about forwarding. So maybe you asked wrong question &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jan 2023 10:07:05 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-01-05T10:07:05Z</dc:date>
    <item>
      <title>Do we need to forward to all indexers in a two site index cluster?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/625967#M26523</link>
      <description>&lt;P&gt;I took over an established Splunk ecosystem when the main support admin retired.&amp;nbsp; I noticed that not all of our stand alone Search Heads, and both Deployment Servers are setup to forward to all 12 of our Indexers in a single multi site Indexer Cluster (see table below)&lt;/P&gt;
&lt;P&gt;Some Search Heads in their &lt;STRONG&gt;outputs.conf&lt;/STRONG&gt; only list the six Indexers that are assigned to &lt;STRONG&gt;Site 1&lt;/STRONG&gt;, while the other Search Heads in their &lt;STRONG&gt;outputs.conf&lt;/STRONG&gt; only list the six Indexers assigned to &lt;STRONG&gt;Site 2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;However all Search Heads in their &lt;STRONG&gt;server.conf&lt;/STRONG&gt; file have this stanza:&lt;BR /&gt;&lt;BR /&gt;[clustering]&lt;BR /&gt;multisite = true&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;So the question is should all of our Splunk Instances aka Search Heads, Cluster Master, and Deployment Servers have all 12 Indexers defined in their &lt;STRONG&gt;outputs.conf&lt;/STRONG&gt; ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="50%" height="25px"&gt;&lt;STRONG&gt;Site 1&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="50%" height="25px"&gt;&lt;STRONG&gt;Site 2&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%" height="25px"&gt;Indexer01&lt;/TD&gt;
&lt;TD width="50%" height="25px"&gt;Indexer07&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%" height="25px"&gt;Indexer02&lt;/TD&gt;
&lt;TD width="50%" height="25px"&gt;Indexer08&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%" height="25px"&gt;Indexer03&lt;/TD&gt;
&lt;TD width="50%" height="25px"&gt;Indexer09&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%" height="25px"&gt;Indexer04&lt;/TD&gt;
&lt;TD width="50%" height="25px"&gt;Indexer10&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%" height="25px"&gt;Indexer05&lt;/TD&gt;
&lt;TD width="50%" height="25px"&gt;Indexer11&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%" height="25px"&gt;Indexer06&lt;/TD&gt;
&lt;TD width="50%" height="25px"&gt;Indexer12&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 17:33:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/625967#M26523</guid>
      <dc:creator>Gregski11</dc:creator>
      <dc:date>2023-01-05T17:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need to Forward to all Indexers in a two site Index Cluster?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/625972#M26524</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232137"&gt;@Gregski11&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry, but a multi site clustered architecture isn't a question for the Community: you need a Splunk Architect or a Splunk Professional Service!&lt;/P&gt;&lt;P&gt;Anyway, see "Affinity" in a Splunk architecture (e.g.&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.3/Indexer/Multisitesearchaffinity" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.3/Indexer/Multisitesearchaffinity&lt;/A&gt;&amp;nbsp;)to answer to your question.&lt;/P&gt;&lt;P&gt;In few words, usually Splunk internal logs are sent to the near indexes, and they reply to the other site Indexers.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 09:17:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/625972#M26524</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-05T09:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need to Forward to all Indexers in a two site Index Cluster?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/625974#M26525</link>
      <description>&lt;P&gt;&lt;EM&gt;Should&lt;/EM&gt; is not a good word to ask about because every environment is different and maybe in some of them you can some options are better than other.&lt;/P&gt;&lt;P&gt;But in general, there's no requirement to direct your outputs to one site or another or both of them. Theoretically, replication should take care about it. That's why you have site SF and site RF - to make the cluster replicate data across the nodes.&lt;/P&gt;&lt;P&gt;It all depends on the distribution of your sources and your sites parameters.&lt;/P&gt;&lt;P&gt;For example, if you have two sites with site SF and RF set as site1:1,site2:1,origin:2, you might want your forwarders to spread the load across sites, otherwise one of the sites will hold more data than the other.&lt;/P&gt;&lt;P&gt;If you had half of your forwarders in site1 and pointing at site1 and another half in site2 pointed at site2, that could be OK but if they were all in site1 and pointed only at site1, you'd end up with site1 holding twice the data of site2 which might not be desired.&lt;/P&gt;&lt;P&gt;So there's no single "right" answer here. It all depends on your requirements and circumstances.&lt;/P&gt;&lt;P&gt;EDIT: Oh, I just noticed you were talking about internal logs from the Splunk environment itself - probably the volume of data won't be that significant compared to the "production" data you'll be ingesting so you might get away with pushing them only to "local" site and it won't matter that much. But again - depends on your requirements for data availability. And yes, I agree with &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; that while Community can give you some general advise, for detailed solution to such topic it's best to employ an Architect. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 09:27:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/625974#M26525</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-01-05T09:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need to Forward to all Indexers in a two site Index Cluster?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/625977#M26526</link>
      <description>&lt;P&gt;thanks Rich I think this link is more my speed, now just to interpret it from Greek to English, lol&lt;BR /&gt;&lt;BR /&gt;&lt;A title="Managing Indexers and Clusters of Indexers" href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Indexer/Configuremulti-clustersearch" target="_self"&gt;Managing Indexers and Clusters of Indexers&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;H2&gt;&lt;SPAN class=""&gt;Configure multi-cluster search for multisite indexer clusters&lt;/SPAN&gt;&lt;/H2&gt;&lt;P&gt;A search head can search across multiple multisite clusters or a combination of single-site and multisite clusters. To configure this, you need to specify the search head's&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;site&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;attribute when connecting it to a multisite cluster.&lt;/P&gt;&lt;H3&gt;&lt;SPAN class=""&gt;By editing server.conf&lt;/SPAN&gt;&lt;/H3&gt;&lt;P&gt;To configure multi-cluster search for a multisite cluster, you need to set two multisite-specific attributes:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;site&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;multisite&lt;/STRONG&gt;. The locations of these attributes vary, depending on a few factors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If the search head will be searching across only multisite clusters, and the search head is on the same site in each cluster,&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;put the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;site&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;attribute under the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[general]&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;stanza and the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;multisite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;attribute under each&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[clustermanager]&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;stanza:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If the search head will be searching across only multisite clusters, and the search head is on a different site in each cluster,&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;put both the&amp;nbsp;&lt;/SPAN&gt;site&lt;SPAN&gt;&amp;nbsp;and the&amp;nbsp;&lt;/SPAN&gt;multisite&lt;SPAN&gt;&amp;nbsp;attributes under the&amp;nbsp;&lt;/SPAN&gt;[clustermanager]&lt;SPAN&gt;&amp;nbsp;stanzas:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;If the search head will be searching across a combination of single-site and multisite clusters,&lt;/STRONG&gt;&amp;nbsp;put both the&amp;nbsp;site&amp;nbsp;and the&amp;nbsp;multisite&amp;nbsp;attributes under the&amp;nbsp;[clustermanager]&amp;nbsp;stanza for any multisite clusters. In this example, the search head searches across two clusters, only one of which is multisite:&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 09:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/625977#M26526</guid>
      <dc:creator>Gregski11</dc:creator>
      <dc:date>2023-01-05T09:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need to Forward to all Indexers in a two site Index Cluster?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/625980#M26527</link>
      <description>&lt;P&gt;OK. But this is about searching, not about forwarding events to indexers and you asked about forwarding. So maybe you asked wrong question &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 10:07:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/625980#M26527</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-01-05T10:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need to forward to all indexers in a two site index cluster?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/627335#M26570</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232137"&gt;@Gregski11&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As a general best practise, the nodes that have &lt;FONT face="courier new,courier"&gt;site = site1&lt;/FONT&gt; in &lt;FONT face="courier new,courier"&gt;[general]&lt;/FONT&gt; stanza in &lt;FONT face="courier new,courier"&gt;server.conf&lt;/FONT&gt;&amp;nbsp; , should have Site1 indexers in their&amp;nbsp;&lt;FONT face="courier new,courier"&gt;outputs.conf&lt;/FONT&gt;&amp;nbsp; . And vice versa. &amp;nbsp;This will prevent log traffic across sites.&lt;/P&gt;&lt;P&gt;If you want a failover capability for forwarding logs you can check the indexer discovery on link below;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.3/Indexer/indexerdiscovery#Use_indexer_discovery_in_a_multisite_cluster" target="_blank"&gt;Use indexer discovery in a multisite cluster&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 11:56:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Do-we-need-to-forward-to-all-indexers-in-a-two-site-index/m-p/627335#M26570</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2023-01-17T11:56:47Z</dc:date>
    </item>
  </channel>
</rss>

