Deployment Architecture

Adding clustered indexers as search peers

atat23
Path Finder

So in versions below 6, you can't add non-clustered search peers to a clustered SH, what about the other way around...?

I can't see a mention of it in the docs, but are there any problems with adding clustered indexers as search peers to a non clustered Splunk instance (stand alone search head/indexer in this case).

I was looking at this previous case were it seems to be possible as the question asker suggest he's done it:
http://answers.splunk.com/answers/101782

I also set up a test scenario with a a clustered test index that I could search from my non clustered instance to my clustered peers, it seemed fine if I searched by index, but had a problem when I tried to search by host (I made sure each of the cluster peers had different data in their test index). So I'm thinking there may be problems with what I'm trying to do that I'm obviously missing.

0 Karma
1 Solution

mahamed_splunk
Splunk Employee
Splunk Employee

Got it. v5 search head won't be able to communicate with v6 clustered indexers.

View solution in original post

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

Got it. v5 search head won't be able to communicate with v6 clustered indexers.

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

I'm not sure i entirely understand the question. Are you wondering if it is possible to use single SH to search a clustered peers and one off non-clustered indexer? If so, then this is possible in v6.

Please refer here

http://docs.splunk.com/Documentation/Splunk/6.0/Indexer/Configurethesearchhead#Search_across_both_cl...

atat23
Path Finder

thanks for the reply. although as stated at the start of my question I was trying to ask if it was possible in versions below version 6, re-reading it, maybe it wasn't clear.

To simplify, the internal requirement was to be able to search a pair of v6 clustered indexers from a v5 search head.

From trawling the docs I was already pretty sure the answer was no, but you never know what this community can come up with 🙂

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...