<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why do we need to set up same instances on every Indexer for Distributed search? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290485#M93733</link>
    <description>&lt;P&gt;Hi Shridhar7Hitesh,&lt;BR /&gt;
I never tested this architecture!&lt;BR /&gt;
In theory it should run, but it isn't a good configuration because you have to use different settings between your two indexers (e.g. paths in indexes.conf) and it's difficoult to manage.&lt;BR /&gt;
When you use a cluster, you're even forced to use the same Splunk version!&lt;/P&gt;

&lt;P&gt;I usually use only Unix servers as Indexers, I use Windows only on my test machine.&lt;/P&gt;

&lt;P&gt;I suggest to use the same operative system on all your infrastructure, at most I used different versions of the same OS (Red Hat 6.4 and 6.6 or 7.0)&lt;/P&gt;

&lt;P&gt;About Splunk versions, at most you can use different versions between Search Heads and Indexers but the same version in the same application level.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 21 Nov 2017 12:35:35 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2017-11-21T12:35:35Z</dc:date>
    <item>
      <title>Why do we need to set up same instances on every Indexer for Distributed search?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290480#M93728</link>
      <description>&lt;P&gt;Let' s say 2 servers behaving as Indexers which have Splunk Enterprise already deployed on them. &lt;/P&gt;

&lt;P&gt;There is one Forwarder and 1 search Head and 2 Server behaving as Indexer and 1 Indexer already so total 3 indexers.&lt;/P&gt;

&lt;P&gt;Why do we need to set up same instances on every Indexer for Distributed search? &lt;/P&gt;

&lt;P&gt;1.) Why do I need to make same instance while Search Head will search from all three (if not specified a particular Indexer.)&lt;/P&gt;

&lt;P&gt;2.) What is the benefit of Data load Balancing in this scenario ( &lt;EM&gt;How data Load will help Search head)&lt;/EM&gt; ?&lt;/P&gt;

&lt;P&gt;Please reply and help me clearing my doubts.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Hitesh. &lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 10:39:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290480#M93728</guid>
      <dc:creator>Shridhar7Hitesh</dc:creator>
      <dc:date>2017-11-20T10:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why do we need to set up same instances on every Indexer for Distributed search?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290481#M93729</link>
      <description>&lt;P&gt;Hi Shridhar7Hitesh,&lt;BR /&gt;
what do you mean with "same instances on every Indexer for Distributed search" ? you can have different indexes in your indexers though it's better to have all the indexes on all Indexers for a better load distribution (see item 2).&lt;/P&gt;

&lt;P&gt;Data Load Balancing has two main advantages: &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;load distribution between different indexes so if there is an overload of ingestion two o three indexers can load quickly a large mass of logs than one (remember that if an indexer is overloaded both ingestion and searches are queued !&lt;/LI&gt;
&lt;LI&gt;Fail over: if one indexer is down the others can ingest logs.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 10:49:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290481#M93729</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-20T10:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why do we need to set up same instances on every Indexer for Distributed search?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290482#M93730</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;

&lt;P&gt;For distributed search I can have different Indexers from which search head will get the desired results. Now these 3 indexers can have different data and different instances. &lt;/P&gt;

&lt;P&gt;My question is why it is important to make same instances on the all of the indexers?&lt;BR /&gt;
{I didn't understand the importance.}&lt;/P&gt;

&lt;P&gt;Load Balancing I understood clearly. Thanks for that. &lt;/P&gt;

&lt;P&gt;Hitesh Shridhar.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 11:43:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290482#M93730</guid>
      <dc:creator>Shridhar7Hitesh</dc:creator>
      <dc:date>2017-11-21T11:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why do we need to set up same instances on every Indexer for Distributed search?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290483#M93731</link>
      <description>&lt;P&gt;Hi Shridhar7Hitesh,&lt;BR /&gt;
Sorry if I repeat my question but I don't understand: &lt;BR /&gt;
what do you mean with "same instances on every Indexer for Distributed search" ? &lt;BR /&gt;
are you speaking of Splunk version or of Indexes?&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 11:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290483#M93731</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-21T11:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why do we need to set up same instances on every Indexer for Distributed search?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290484#M93732</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;

&lt;P&gt;Is it possible that 1 server is *NIX ( Splunk Enterprise) deployed as Indexer and 1 server has windows (Splunk Enterprise) deployed as Indexer and then both can communicate properly being search peers?&lt;/P&gt;

&lt;P&gt;Actually I am also not sure, what doe "same instances mean". I am trying to find that as well. &lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Hitesh&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 12:24:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290484#M93732</guid>
      <dc:creator>Shridhar7Hitesh</dc:creator>
      <dc:date>2017-11-21T12:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why do we need to set up same instances on every Indexer for Distributed search?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290485#M93733</link>
      <description>&lt;P&gt;Hi Shridhar7Hitesh,&lt;BR /&gt;
I never tested this architecture!&lt;BR /&gt;
In theory it should run, but it isn't a good configuration because you have to use different settings between your two indexers (e.g. paths in indexes.conf) and it's difficoult to manage.&lt;BR /&gt;
When you use a cluster, you're even forced to use the same Splunk version!&lt;/P&gt;

&lt;P&gt;I usually use only Unix servers as Indexers, I use Windows only on my test machine.&lt;/P&gt;

&lt;P&gt;I suggest to use the same operative system on all your infrastructure, at most I used different versions of the same OS (Red Hat 6.4 and 6.6 or 7.0)&lt;/P&gt;

&lt;P&gt;About Splunk versions, at most you can use different versions between Search Heads and Indexers but the same version in the same application level.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 12:35:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290485#M93733</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-21T12:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why do we need to set up same instances on every Indexer for Distributed search?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290486#M93734</link>
      <description>&lt;P&gt;That makes sense. But I really wonder that how much difficulty it might contain to use. &lt;BR /&gt;
Thanks for the answer and clarification. &lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
Hitesh Shridhar.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 09:20:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-do-we-need-to-set-up-same-instances-on-every-Indexer-for/m-p/290486#M93734</guid>
      <dc:creator>Shridhar7Hitesh</dc:creator>
      <dc:date>2017-11-22T09:20:29Z</dc:date>
    </item>
  </channel>
</rss>

