<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: peer nodes vs. indexer nodes in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185577#M7753</link>
    <description>&lt;P&gt;Please accept this answer with the check box if it meets your needs.  Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 19 Dec 2013 16:57:23 GMT</pubDate>
    <dc:creator>dmaislin_splunk</dc:creator>
    <dc:date>2013-12-19T16:57:23Z</dc:date>
    <item>
      <title>peer nodes vs. indexer nodes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185570#M7746</link>
      <description>&lt;P&gt;Basic / understanding question here. &lt;BR /&gt;
The documentation refers to both indexer and peer nodes. After reading it is true that:&lt;BR /&gt;
 Peer nodes are indexers and that all peer nodes also have indexer functionality;&lt;BR /&gt;
 Peer nodes also replicate data to other peer nodes?&lt;BR /&gt;
Do all peer nodes serve as indexers - are the other responsibility / functionality  differences between peers and indexers? Is there a concept as a "straight indexer node"?&lt;BR /&gt;
A RTFM response is fine &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; just point me to a page (please).&lt;BR /&gt;
Thx.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 16:25:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185570#M7746</guid>
      <dc:creator>tim_snider</dc:creator>
      <dc:date>2013-12-19T16:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: peer nodes vs. indexer nodes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185571#M7747</link>
      <description>&lt;P&gt;Sorry for the confusion.  Peer nodes are your indexers.  They are all peers to each other.  The search head sends a search down to the peers where the peers(indexer) run the search and return the results back to the search head.  If you also have a Splunk cluster defined, then you can tell your indexers to make N number of copies of the indexed data across the peers.  This can have a replication factor and a search factor where a search factor also replicates the meta data.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 16:41:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185571#M7747</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2013-12-19T16:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: peer nodes vs. indexer nodes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185572#M7748</link>
      <description>&lt;P&gt;Well you are basically right. When setting up Distributed Search, with a dedicated Search Head, and one or more Indexers, those Indexers are referred to as "search peers", whereas in a cluster setup, the servers that are indexing incoming data and replicating indexed data between themselves are referred to as "peer nodes". In a single server setup, there will be no peers, just a combined search head/indexer.&lt;/P&gt;

&lt;P&gt;So yes, you could say that indexer = peer, but if you want to thoroughly correct, I believe you could say that an indexer indexes data, and the peer responds to remote requests for data. It's all about which point of view you have. &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Splexicon:Peernode"&gt;http://docs.splunk.com/Splexicon:Peernode&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Splexicon:Searchpeer"&gt;http://docs.splunk.com/Splexicon:Searchpeer&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Splexicon:Indexer"&gt;http://docs.splunk.com/Splexicon:Indexer&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 16:49:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185572#M7748</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-12-19T16:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: peer nodes vs. indexer nodes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185573#M7749</link>
      <description>&lt;P&gt;dang. late again!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 16:50:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185573#M7749</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-12-19T16:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: peer nodes vs. indexer nodes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185574#M7750</link>
      <description>&lt;P&gt;no problem - thx for the response. Is data replicated for data availability  in case of hardware failure, additional indexing capability, or both?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 16:52:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185574#M7750</guid>
      <dc:creator>tim_snider</dc:creator>
      <dc:date>2013-12-19T16:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: peer nodes vs. indexer nodes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185575#M7751</link>
      <description>&lt;P&gt;Replicated for data availability.  A search does not run parallel if the data exists in two places at once.  The cluster master tells the search head which places to go get the data.  If something goes down, the cluster master updates the list of peers to search.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 16:55:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185575#M7751</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2013-12-19T16:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: peer nodes vs. indexer nodes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185576#M7752</link>
      <description>&lt;P&gt;But you included the links &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 16:56:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185576#M7752</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2013-12-19T16:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: peer nodes vs. indexer nodes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185577#M7753</link>
      <description>&lt;P&gt;Please accept this answer with the check box if it meets your needs.  Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 16:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/peer-nodes-vs-indexer-nodes/m-p/185577#M7753</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2013-12-19T16:57:23Z</dc:date>
    </item>
  </channel>
</rss>

