Deployment Architecture

DMC: Search heads shown as heavy forwarders?

cdoebert
Path Finder

I'm in a setup with a license/deployment server, three clustered search heads and a deployer, and three non-clustered indexers.

Per the documentation on setting up the DMC, I'm setting it up on the deployer. It picked up the indexers, but I can't get it to pick up my search heads and I'm not sure why. When I turn on forwarder monitoring, my search heads show up as heavy forwarders.

How do I get the search heads to show up in the DMC?

Tags (1)
0 Karma
1 Solution

cdoebert
Path Finder

This is fixed in an extremely odd way. I had to edit the server roles for the license/deployment server (even though it picked them up automatically) so I could get the error for a deployment server to have another role and accept it, and then all the servers that weren't indexers graduated from "New" to "Configured".

View solution in original post

0 Karma

cdoebert
Path Finder

This is fixed in an extremely odd way. I had to edit the server roles for the license/deployment server (even though it picked them up automatically) so I could get the error for a deployment server to have another role and accept it, and then all the servers that weren't indexers graduated from "New" to "Configured".

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

Add those as search peers.

Try this

http://docs.splunk.com/Documentation/Splunk/6.4.3/DMC/Addinstancesassearchpeers

Happy Splunking!

cdoebert
Path Finder

I followed that and added the entire environment, and everything shows up in the general setup tab, but I still see only the indexers in the overview and none of the other tabs (aside from indexing) work.

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2023 Splunk Career Impact Report

We’ve been shouting it from the rooftops! The findings from the 2023 Splunk Career Impact Report showing that ...

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...