Deployment Architecture

Choosing "settings" - "indexer clustering" takes me to "Clustering: Search Head"; possible to fix?

mitag
Contributor

In our on-prem splunk cluster attempting to follow these steps in "Enable the peer nodes":

Enable the peer
To enable an indexer as a peer node:
1. Click Settings in the upper right corner of Splunk Web.
2. In the Distributed environment group, click Indexer clustering.
3. Select Enable indexer clustering.

... like this:

Indexer clustering

... takes me instead to a page called "Clustering: Search Head" where there's no option to "Enable indexer clustering" nor to add a new indexer to a given cluster.

Clustering: Search Head

I am assuming something's not right with our cluster configuration. Any idea how to fix it?

P.S. Context: the goal is to add a new indexer to the existing cluster from scratch (it's a freshly deployed CentOS 7 VM with no data and installed-but-not-yet-started Splunk Enterprise). However I am having difficulties following the available documentation given that the steps in it lead me to unexpected results - like what I described above.

Thanks!

Labels (3)
0 Karma

anthonymelita
Contributor

If you are seeing that page it means you have the node configured as a Search head.
Click on Edit > Node Type
There you will be able to configure it as a Peer node

0 Karma

mitag
Contributor

Thanks - I am still confused. The web page I am on is hosted by a SH node on a production cluster. If I go to "Edit > Node type" and change the configuration to, say, "peer node" - will it reconfigure the SH as an indexer? (Definitely not what I want to do. This will break things, people will get mad at me, and I may not live till tomorrow.)

P.S. Splunk web is only running on the search head and nowhere else. All other roles (Masters, DS, Monitoring, Indexers) are configured not to run Splunk web.

Thanks!

0 Karma

anthonymelita
Contributor

Correct, it would change the local instance to an indexer member. It does not allow you to perform remote administration of other peers. If you aren't running Splunk web on your indexers then you'll need to use one of the other methods listed in the docs.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...