All Apps and Add-ons

EMC Isilon Add-on for Splunk Enterprise: Setup multiple clusters?

amirofmn
Explorer

We have successfully configured the EMC Isilon Add-on for Splunk Enterprise in our distributed environment and is currently pulling data from one cluster/site. If we want to add a second cluster/site into the Add-on, do we just enter the information of the second cluster/site in the 'Add any of the Cluster node credentials' page or will that overwrite our current setup?

0 Karma
1 Solution

pjvarjani
Path Finder

Hi,

You can add the second cluster through setup page of Add-on. It would not overwrite the previous configurations. Both EMC Isilon Add-on and App are designed in a such a way that they support multiple Isilon clusters.

Thanks,
Pankaj

View solution in original post

0 Karma

pjvarjani
Path Finder

Hi,

You can add the second cluster through setup page of Add-on. It would not overwrite the previous configurations. Both EMC Isilon Add-on and App are designed in a such a way that they support multiple Isilon clusters.

Thanks,
Pankaj

0 Karma

amirofmn
Explorer

Thanks for the response. We entered the second cluster/site and it worked!

If we need to remove any old/outdated cluster information from the Add-on, is the best way going to be deleting/disabling all the inputs?

0 Karma

pjvarjani
Path Finder

Hi,

Yes you can disable all the inputs for that cluster/node. I would suggest better solution though.

On your Heavy Forwarder/Data collection node,

  1. Remove the entry of input stanzas for the unwanted cluster/node from TA_EMC-Isilon/local/inputs.conf(take backup first)
  2. remove the stanza for unwanted cluster/node from TA_EMC-Isilon/local/passwords.conf.
  3. Restart Splunk

Thanks,
Pankaj

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...