Deployment Architecture

Adding clustered indexers as search peers

atat23
Path Finder

So in versions below 6, you can't add non-clustered search peers to a clustered SH, what about the other way around...?

I can't see a mention of it in the docs, but are there any problems with adding clustered indexers as search peers to a non clustered Splunk instance (stand alone search head/indexer in this case).

I was looking at this previous case were it seems to be possible as the question asker suggest he's done it:
http://answers.splunk.com/answers/101782

I also set up a test scenario with a a clustered test index that I could search from my non clustered instance to my clustered peers, it seemed fine if I searched by index, but had a problem when I tried to search by host (I made sure each of the cluster peers had different data in their test index). So I'm thinking there may be problems with what I'm trying to do that I'm obviously missing.

0 Karma
1 Solution

mahamed_splunk
Splunk Employee
Splunk Employee

Got it. v5 search head won't be able to communicate with v6 clustered indexers.

View solution in original post

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

Got it. v5 search head won't be able to communicate with v6 clustered indexers.

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

I'm not sure i entirely understand the question. Are you wondering if it is possible to use single SH to search a clustered peers and one off non-clustered indexer? If so, then this is possible in v6.

Please refer here

http://docs.splunk.com/Documentation/Splunk/6.0/Indexer/Configurethesearchhead#Search_across_both_cl...

atat23
Path Finder

thanks for the reply. although as stated at the start of my question I was trying to ask if it was possible in versions below version 6, re-reading it, maybe it wasn't clear.

To simplify, the internal requirement was to be able to search a pair of v6 clustered indexers from a v5 search head.

From trawling the docs I was already pretty sure the answer was no, but you never know what this community can come up with 🙂

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...