<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Properly configuring the Monitoring Console in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Properly-configuring-the-Monitoring-Console/m-p/761943#M11154</link>
    <description>&lt;P&gt;My recommendation is add all HFs, HECs etc as indexers into mc. Then create need subgroups to divide those to reasonable logical sets. Now you can use those groups when you’re selecting target servers in different dashboards. In this way your life is much easier than trying to use on SPL or even separate dashboards.&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jun 2026 21:45:55 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2026-06-25T21:45:55Z</dc:date>
    <item>
      <title>Properly configuring the Monitoring Console</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Properly-configuring-the-Monitoring-Console/m-p/761861#M11151</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a hopefully quick and basic question, I read the following two docs but I am still not quite clear on how and where I should add the SHs and standalone SH instance:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console/add-splunk-enterprise-instances-to-the-monitoring-console

https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console/configure-the-monitoring-console-in-distributed-mode&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Specifically, we have a Cluster Manager that has a configured MC, with the indexer cluster, fine but there is also a MC on our DS with the same indexers added. So, where would I add the SHs and HFs? I do not want to break the existing configuration but also want to understand this better.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 19:26:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Properly-configuring-the-Monitoring-Console/m-p/761861#M11151</guid>
      <dc:creator>JohnEGones</dc:creator>
      <dc:date>2026-06-23T19:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Properly configuring the Monitoring Console</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Properly-configuring-the-Monitoring-Console/m-p/761863#M11152</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258618"&gt;@JohnEGones&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why do you have the MC configured on two different instances? You should really consolidate into a single MC and then take it from there. Check out&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/monitor/10.4/configure-the-monitoring-console/which-instance-should-host-the-console" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/administer/monitor/10.4/configure-the-monitoring-console/which-instance-should-host-the-console&lt;/A&gt;&amp;nbsp;for recommended MC setup locations.&lt;/P&gt;&lt;P&gt;Once consolidated you can add the SH/HF.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you? If so, please consider&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 22:08:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Properly-configuring-the-Monitoring-Console/m-p/761863#M11152</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-06-23T22:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: Properly configuring the Monitoring Console</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Properly-configuring-the-Monitoring-Console/m-p/761867#M11153</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258618"&gt;@JohnEGones&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;to properly configure the MC, you must connect it to the CM, in this way you have the CM and all the IDXs.&lt;/P&gt;&lt;P&gt;Then you have to connect one by one all the SHs and (if present) the SHC-Deployer, at least the DS.&lt;/P&gt;&lt;P&gt;Beware to a point of attention: it isn't a best practice to put the MC on the DS, particurarly if it has to manage more than 50 clients, it's better to put it on a dedicated server, or on the SHC-Deployer, or, if you have not very large data volumes on the CM: I usually put it on the SHC-Deployer.&lt;/P&gt;&lt;P&gt;About Heavy Forwarders, they are usually not directly monitored by the MC: I usually create some custom dashboards to have all the information that I need and I'm not sure that connecting them to the MC you have the requested inormation.&lt;/P&gt;&lt;P&gt;For more information to connect the MC to the other components see at&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console/configure-the-monitoring-console-in-distributed-mode" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console/configure-the-monitoring-console-in-distributed-mode&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 06:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Properly-configuring-the-Monitoring-Console/m-p/761867#M11153</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2026-06-24T06:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Properly configuring the Monitoring Console</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Properly-configuring-the-Monitoring-Console/m-p/761943#M11154</link>
      <description>&lt;P&gt;My recommendation is add all HFs, HECs etc as indexers into mc. Then create need subgroups to divide those to reasonable logical sets. Now you can use those groups when you’re selecting target servers in different dashboards. In this way your life is much easier than trying to use on SPL or even separate dashboards.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2026 21:45:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Properly-configuring-the-Monitoring-Console/m-p/761943#M11154</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2026-06-25T21:45:55Z</dc:date>
    </item>
  </channel>
</rss>

