All Apps and Add-ons

EMC Isilon Add-on for Splunk Enterprise: Setup multiple clusters?

amirofmn
Explorer

We have successfully configured the EMC Isilon Add-on for Splunk Enterprise in our distributed environment and is currently pulling data from one cluster/site. If we want to add a second cluster/site into the Add-on, do we just enter the information of the second cluster/site in the 'Add any of the Cluster node credentials' page or will that overwrite our current setup?

0 Karma
1 Solution

pjvarjani
Path Finder

Hi,

You can add the second cluster through setup page of Add-on. It would not overwrite the previous configurations. Both EMC Isilon Add-on and App are designed in a such a way that they support multiple Isilon clusters.

Thanks,
Pankaj

View solution in original post

0 Karma

pjvarjani
Path Finder

Hi,

You can add the second cluster through setup page of Add-on. It would not overwrite the previous configurations. Both EMC Isilon Add-on and App are designed in a such a way that they support multiple Isilon clusters.

Thanks,
Pankaj

0 Karma

amirofmn
Explorer

Thanks for the response. We entered the second cluster/site and it worked!

If we need to remove any old/outdated cluster information from the Add-on, is the best way going to be deleting/disabling all the inputs?

0 Karma

pjvarjani
Path Finder

Hi,

Yes you can disable all the inputs for that cluster/node. I would suggest better solution though.

On your Heavy Forwarder/Data collection node,

  1. Remove the entry of input stanzas for the unwanted cluster/node from TA_EMC-Isilon/local/inputs.conf(take backup first)
  2. remove the stanza for unwanted cluster/node from TA_EMC-Isilon/local/passwords.conf.
  3. Restart Splunk

Thanks,
Pankaj

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...