<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Distributed Summary Indexing from Search Head in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82349#M2953</link>
    <description>&lt;P&gt;Excellent. That's exactly what I was looking for, and I forgot to mention that we do use custom named summary indexes. I will try the setup as you suggest and report back. Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 03 Nov 2010 02:47:23 GMT</pubDate>
    <dc:creator>mattcg</dc:creator>
    <dc:date>2010-11-03T02:47:23Z</dc:date>
    <item>
      <title>Distributed Summary Indexing from Search Head</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82347#M2951</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm looking to set up our search head to send summary index data it generates back to our indexers in a distributed environment. &lt;/P&gt;

&lt;P&gt;I found the following question, and I understand the theory of the answer. However, I don't know specifically how to set up the search head as a forwarder and how to tell it to forward the summaries generated instead of indexing them.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/questions/5837/summary-indexing-on-a-search-head" rel="nofollow"&gt;http://answers.splunk.com/questions/5837/summary-indexing-on-a-search-head&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Furthermore, is Splunk intelligent enough to determine that summaries generated by a search head and then forwarded back down to our indexers are summaries and therefore not count them toward our license?&lt;/P&gt;

&lt;P&gt;Thanks for any guidance.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2010 00:35:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82347#M2951</guid>
      <dc:creator>mattcg</dc:creator>
      <dc:date>2010-11-03T00:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Summary Indexing from Search Head</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82348#M2952</link>
      <description>&lt;P&gt;Hi Matt -
  Having gone through this before, I can say that anything forwarded from the Search head to the indexers is &lt;EM&gt;NOT&lt;/EM&gt; counted toward your license cost.  You can even set up the Search head to use the forwarder license included with the app.&lt;/P&gt;

&lt;P&gt;With regards to setting up the Search head as a forwarder, it's the same process as you would use for any other forwarder.  You can find the details here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Setupforwardingandreceiving#Set_up_forwarding_and_receiving:_heavy_or_light_forwarders" rel="nofollow"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Setupforwardingandreceiving#Set_up_forwarding_and_receiving:_heavy_or_light_forwarders&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;Now, there's one caveat.  If you use custom named summary indexes, you'll have to make sure they're created in the indexes.conf on the Indexers as well.&lt;/P&gt;

&lt;P&gt;Hope this helps!
Brian&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2010 02:40:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82348#M2952</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2010-11-03T02:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Summary Indexing from Search Head</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82349#M2953</link>
      <description>&lt;P&gt;Excellent. That's exactly what I was looking for, and I forgot to mention that we do use custom named summary indexes. I will try the setup as you suggest and report back. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2010 02:47:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82349#M2953</guid>
      <dc:creator>mattcg</dc:creator>
      <dc:date>2010-11-03T02:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Summary Indexing from Search Head</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82350#M2954</link>
      <description>&lt;P&gt;Not &lt;CODE&gt;everything&lt;/CODE&gt; forwarded from a SH to an indexer is license free - only things that are license-free anyways, such as internal logs and summary indexing. It is possible to bust a forwarder license with something like the UNIX app inputs and no indexer to forward to!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2011 22:39:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82350#M2954</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2011-04-14T22:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Summary Indexing from Search Head</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82351#M2955</link>
      <description>&lt;P&gt;I have also tried the same. I have a srch head and two indexers. I tried to forward the summary index from the srch head to both the indexers. Now for one of the Indxers it is working fine but for the other one it is not working.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2012 17:40:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82351#M2955</guid>
      <dc:creator>Splunk_U</dc:creator>
      <dc:date>2012-12-14T17:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Summary Indexing from Search Head</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82352#M2956</link>
      <description>&lt;P&gt;I did it and internal,audit , introspection also copied to indexer, how can I change configuration in the way it exclude internal indexes&lt;/P&gt;</description>
      <pubDate>Sun, 28 Apr 2019 06:48:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Summary-Indexing-from-Search-Head/m-p/82352#M2956</guid>
      <dc:creator>sabaKhadivi</dc:creator>
      <dc:date>2019-04-28T06:48:12Z</dc:date>
    </item>
  </channel>
</rss>

