Splunk Enterprise

Do i create indexs on Search head or on each indexer on non cluster envioment

smdasim
Explorer

Hi,

We have a indexer{2 indexers] in our environment, 2 fowarder and 1 search heads. If we create indexes on a search head using GUI will the configuration for these be reflected in indexers?

Please advice detailed steps to create indexs in a simple splunk envioment with 1 Search head ,2 Fowarders and 2 Indexers .

Regards
smdasim

Tags (1)
0 Karma

afroz
Path Finder

Hi,

Create indexes in each indexer at /etc/apps folder.

From search head go to settings - search peers--> add indexers with management port.

Forward data from forwarders to indexers directly.

Logs will be searchable from search head. No need to create index in search head. Just add indexers in search peers of search head as explained above.

renjith_nair
Legend

@smdasim,

There is no difference in the splunk software for search head and index. Its the configuration what it make the difference and assign the roles.

Indexes created on search head do not transfer to indexers automatically. You need to create index on the indexers manually or use a deployment server to push the indexes.conf automatically.

Since its a distributed architecture, you could decide which data goes to which indexer and index and based on that you can create index on specific indexers using Splunk Web or cli or using indexes.conf

Here is a detailed documentation about creating index in distributed environment.

http://docs.splunk.com/Documentation/Splunk/7.1.2/Indexer/Setupmultipleindexes#Create_and_edit_event...

Also its recommended to send search head data also to indexers . Detailed steps are available in
https://docs.splunk.com/Documentation/Splunk/7.1.2/DistSearch/Forwardsearchheaddata

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...