Deployment Architecture

Distributed Search using a VIP ip address on an HA pair to another HA Pair

tier2ops
Explorer

So I have two ha pairs that I want to set distributes searches on:

Pair-A-1 10.10.10.5
Pair-A-2 10.10.10.6
VIP 10.10.10.7

Pair-B-1 172.16.1.11
Pair-B-2 172.16.1.12
VIP 172.16.1.13

How do I setup the peers?

Pair-A-1:

Peer 172.16.1.13:8089 (By Vip)

or

Peer Pair-B-1:8089 (or Peer 172.16.1.11:8089)

Peer Pair-B-2:8089 (or Peer 172.16.1.12:8089)

Tags (1)

araitz
Splunk Employee
Splunk Employee

If I understand you question correctly, you will need to share the search head's distsearch key out to each of the nodes:

http://www.splunk.com/base/Documentation/latest/Admin/Configuredistributedsearch#Distribute_the_key_...

After that, your distsearch.conf should look something like this:

[distributedSearch]
heartbeatFrequency = 10
servers = 10.10.10.7:8089,172.16.1.13:8089
0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...