<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Run indexes on different servers in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283038#M54102</link>
    <description>&lt;P&gt;We are planning to have a Splunk setup where we have:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;1 server running a Splunk indexer&lt;/LI&gt;
&lt;LI&gt;2 servers per operation from which log files are forwarded by universal indexers&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/745i5DE073B191725030/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;We are then planing to store each operations index on the operations own server instead of on the Splunk indexer.&lt;BR /&gt;
All servers are on the same network.&lt;/P&gt;

&lt;P&gt;Is this setup doable?&lt;/P&gt;</description>
    <pubDate>Mon, 19 Oct 2015 12:27:29 GMT</pubDate>
    <dc:creator>carljohan</dc:creator>
    <dc:date>2015-10-19T12:27:29Z</dc:date>
    <item>
      <title>Run indexes on different servers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283038#M54102</link>
      <description>&lt;P&gt;We are planning to have a Splunk setup where we have:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;1 server running a Splunk indexer&lt;/LI&gt;
&lt;LI&gt;2 servers per operation from which log files are forwarded by universal indexers&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/745i5DE073B191725030/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;We are then planing to store each operations index on the operations own server instead of on the Splunk indexer.&lt;BR /&gt;
All servers are on the same network.&lt;/P&gt;

&lt;P&gt;Is this setup doable?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 12:27:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283038#M54102</guid>
      <dc:creator>carljohan</dc:creator>
      <dc:date>2015-10-19T12:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Run indexes on different servers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283039#M54103</link>
      <description>&lt;P&gt;The indexer needs direct access to the location where you are going to store the data. So if you are in a Linux environment, you'd have to mount the drive from the "DB Servers" on your Splunk indexer server(s). Then make sure you define in indexes.conf the correct paths using the mounts. &lt;/P&gt;

&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 12:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283039#M54103</guid>
      <dc:creator>aholzer</dc:creator>
      <dc:date>2015-10-19T12:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Run indexes on different servers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283040#M54104</link>
      <description>&lt;P&gt;Hi Carljohan, You would not want to necessarily forward the DB logs to the central Splunk Instance. You could have op1 and op2 DBs just index locally, and then set the central Splunk instance up to search each of the DB instances, while still forwarding the app boxes to the central Splunk server.  Other than that I can't detect any issue with this setup.&lt;/P&gt;

&lt;P&gt;Let me know if this helps &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 13:07:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283040#M54104</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2015-10-19T13:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Run indexes on different servers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283041#M54105</link>
      <description>&lt;P&gt;Thanks Muebei. But that would require us to do a full Splunk install on the DB servers, not only a universal forwarder. Right?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 13:17:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283041#M54105</guid>
      <dc:creator>carljohan</dc:creator>
      <dc:date>2015-10-19T13:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: Run indexes on different servers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283042#M54106</link>
      <description>&lt;P&gt;The only way to "do" it this way is to somehow have your Forwarders' storage directly accessible by your Indexers which I do not see how you will be able to do it other than if you use NFS and mount to both systems.  This means your Forwarders will host the Indexer's write operations only.  The other way to make it work is to configure your Forwarders to also be Indexers which I think is a VERY bad idea because the Indexers are the ones that always (eventually) get overloaded with work and slow to a crawl which will adversely impact the job that those servers are (primarily) supposed to be doing.  Why are you using such a strange (bad) constraint?  Anyway you do this, it is a pretty bad idea and, to quote a splunk T-shirt, you are "looking for trouble".&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 13:20:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283042#M54106</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-19T13:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: Run indexes on different servers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283043#M54107</link>
      <description>&lt;P&gt;Thank you for your feedback. &lt;/P&gt;

&lt;P&gt;The data from the different operations need to be separated due to contractual reasons.&lt;BR /&gt;
Any suggestion on how we can accomplish that in a less strange (bad) way?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 13:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283043#M54107</guid>
      <dc:creator>carljohan</dc:creator>
      <dc:date>2015-10-19T13:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Run indexes on different servers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283044#M54108</link>
      <description>&lt;P&gt;Yup, the universal forwarder doesn't have any local indexing capability, it can only forward events.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 14:02:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283044#M54108</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2015-10-19T14:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Run indexes on different servers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283045#M54109</link>
      <description>&lt;P&gt;What you are actually desiring is known as &lt;CODE&gt;Mutitenancy&lt;/CODE&gt;.  Check out these links (or do your own search):&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Updating/Deployinmulti-tenantenvironments"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Updating/Deployinmulti-tenantenvironments&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://wiki.splunk.com/Community:Multi-tenant_scenario"&gt;https://wiki.splunk.com/Community:Multi-tenant_scenario&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/127073/indexing-best-practices-for-multi-tenant-environment-and-various-apps.html"&gt;https://answers.splunk.com/answers/127073/indexing-best-practices-for-multi-tenant-environment-and-various-apps.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2011/11/04/splunk-and-multitenancy/"&gt;http://blogs.splunk.com/2011/11/04/splunk-and-multitenancy/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 15:02:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283045#M54109</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-19T15:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Run indexes on different servers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283046#M54110</link>
      <description>&lt;P&gt;See my latest answer regarding &lt;CODE&gt;Multitenancy&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 15:03:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Run-indexes-on-different-servers/m-p/283046#M54110</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-19T15:03:14Z</dc:date>
    </item>
  </channel>
</rss>

