Deployment Architecture

Cluster Master and Forwarding?

gschmitz
Path Finder

Hi,
I set up a couple of inputs on my cluster master and I do see it collecting data in the logs.
However even after activating Heavy and Light Forwarder modes as per the wiki (http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Forwardercapabilities) I don't even see it trying to connect to the indexers (i.e. its slaves)?
Am I doing something wrong? Do I have to deploy a universal forwarder next to the master in order to monitor it?

nromito_splunk
Splunk Employee
Splunk Employee

Since the master is supposed to solely control the activities of the index cluster, it is recommended that you don't add extra work for the master to do. If you absolutely need to monitor these few files on the cluster master, I would recommend following this documentation (http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Forwardmasterdata).

It is best practice to forward all of the master's logs to the peers, so the master does not have to be bogged down with any indexing itself.

0 Karma

psow_splunk
Splunk Employee
Splunk Employee

The master is designed to function solely as the cluster manager. But I have no issues configuring it to monitor certain path and forwarding it to the indexers in the cluster. So it will still work

0 Karma

Steve_G_
Splunk Employee
Splunk Employee

The master is designed to function solely as the cluster manager. It's not a good idea to ask it to index external data; that's the job of the peer nodes.

The master will index its own internal data, of course, which you can access directly on the master. The master dashboard should handle most of your monitoring needs. I suppose you could configure an outputs.conf file on the master to forward that data to some other instance, if necessary, but don't set the master up as a heavy or light forwarder.

gschmitz
Path Finder

In fact enabling these apps switches off replication. Will continue at a later point in time to investigate this. If somebody has a working configuration for this, you are very much invited to post it though!

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...