<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk architecture question in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349468#M64153</link>
    <description>&lt;P&gt;One last question : I have often this message "waiting for requisite number of peers to join the cluster" on the test environment as there isn't any indexer on the test cluster master (that CM will be used to deploy SH configurations/apps).&lt;/P&gt;

&lt;P&gt;Also why my management servers (cluster masters) are listed in 'search heads' on the &lt;A href="https://docs.splunk.com/images/8/8d/Master_dashboard_6.1.png"&gt;master dashboard&lt;/A&gt;?&lt;/P&gt;

&lt;P&gt;Thanks a lot.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Nov 2017 23:57:54 GMT</pubDate>
    <dc:creator>splunkreal</dc:creator>
    <dc:date>2017-11-03T23:57:54Z</dc:date>
    <item>
      <title>Splunk architecture question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349461#M64146</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;  Could you let us know if it’s possible to connect one cluster master to another cluster indexers using distributed search or clustering settings?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Example :&lt;/P&gt;

&lt;P&gt;testenvmgt1 (management/cluster master/shc deployer)&lt;BR /&gt;&lt;BR /&gt;
testenvsh1 (search head/kv)                                                                                              ------------------------------------&amp;gt;  productionenvidx1/productionenvidx2 (in another cluster)&lt;BR /&gt;
testenvsh2 (search head/kv)                             &lt;/P&gt;

&lt;P&gt;testenv hasn’t any indexer.&lt;/P&gt;

&lt;P&gt;I think we can use distributed search but I’m afraid we may get duplicate results without being in a cluster?&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;  Also which replication/search factor should we use (1?) as we don’t have 3 SHs as documented.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 02 Nov 2017 13:33:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349461#M64146</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2017-11-02T13:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk architecture question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349462#M64147</link>
      <description>&lt;P&gt;OK, it sounds like you have a test environment with a partial search head cluster that you want to search your production indexer cluster.  In that case, assuming that you have a separate cluster master for your production indexer cluster, the replication and search factor on your test environment cluster master won't do anything since it is not controlling any test indexers.  The replication and search factors on your test cluster master also will not have any affect on your test search heads.&lt;/P&gt;

&lt;P&gt;That said, you should be able to configure server.conf via the deployer on your test search heads to search your production indexer cluster, you'll just need to make sure that the plain text value of pass4SymKey matches between the two.  You'd have to point it to your production cluster master because your test cluster master (hopefully) isn't controlling your production indexers.&lt;/P&gt;

&lt;P&gt;As far as having both cluster masters control your production indexers, the indexers would only be able to point to a single cluster master to control their configurations and replication behavior.  Even if they could talk to both, you wouldn't want testing in your lab to be potentially breaking things on your production indexer cluster.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 13:46:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349462#M64147</guid>
      <dc:creator>traxxasbreaker</dc:creator>
      <dc:date>2017-11-02T13:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk architecture question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349463#M64148</link>
      <description>&lt;P&gt;Hello traxxasbreaker, do you mean enabling test search heads as shown at &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Enablethesearchhead"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Enablethesearchhead&lt;/A&gt;? If yes, is it from the testenv cluster master (Distributed environment/Indexer clustering/Node type/Search head node)&lt;/P&gt;

&lt;P&gt;Or is it adding each production indexer in the test cluster master distributed search? (Distributed Environment/Distributed search)&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 14:18:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349463#M64148</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2017-11-02T14:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk architecture question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349464#M64149</link>
      <description>&lt;P&gt;Yes, like that document.  You would be doing it from your deployer in your lab environment within an app that you would push out to your search head cluster members.  You should not add your production indexers to your test cluster master.  &lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 21:05:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349464#M64149</guid>
      <dc:creator>traxxasbreaker</dc:creator>
      <dc:date>2017-11-02T21:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk architecture question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349465#M64150</link>
      <description>&lt;P&gt;If you want to search an indexer cluster, you have to connect your SH to the corresponding Cluster Master.&lt;BR /&gt;
There is no issue making a SH be search two (or more) separate indexer clusters; just add both cluster masters to your search head configuration. This is &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Configuremulti-clustersearch"&gt;documented here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 22:02:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349465#M64150</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-11-02T22:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk architecture question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349466#M64151</link>
      <description>&lt;P&gt;Thanks a lot! So is it from each test search head to the production cluster master (management)?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 11:33:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349466#M64151</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2017-11-03T11:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk architecture question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349467#M64152</link>
      <description>&lt;P&gt;Yes, do it on every search head that needs to search your production index cluster.&lt;BR /&gt;
For SHC, take a look &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/SHCandindexercluster"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 17:31:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349467#M64152</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-11-03T17:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk architecture question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349468#M64153</link>
      <description>&lt;P&gt;One last question : I have often this message "waiting for requisite number of peers to join the cluster" on the test environment as there isn't any indexer on the test cluster master (that CM will be used to deploy SH configurations/apps).&lt;/P&gt;

&lt;P&gt;Also why my management servers (cluster masters) are listed in 'search heads' on the &lt;A href="https://docs.splunk.com/images/8/8d/Master_dashboard_6.1.png"&gt;master dashboard&lt;/A&gt;?&lt;/P&gt;

&lt;P&gt;Thanks a lot.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 23:57:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-architecture-question/m-p/349468#M64153</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2017-11-03T23:57:54Z</dc:date>
    </item>
  </channel>
</rss>

