Deployment Architecture

Distributed deployment and MC: Do I need to add SH if the SH is sending its data to IDX cluster?

MLGSPLUNK
Path Finder

Hi community.

Just preparing for my ARCH practical lab. I heard that it's mandatory to add to the MC the non clustered SH as a search peer. However, I already configured the SH to send its internal data to the IDX cluster I have deployed.

My question is: Do I need to also configure the SH as a search peer on the MC in order to be able to monitor it, or just with the cluster master as a search peer (it automatically adds all the clustered idx to the MC) will it do.

In theory if all the SH _internal data is at the IDX layer, the MC would take a look at the IDX cluster that contains the aleady forwarded _internal data from the SH, ritght?

Please provide an explanation so I can beat the practical lab. Thanks!

0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @MLGSPLUNK,

MC is using REST calls to monitor Splunk Servers. That is why it should be able to access all Splunk Instances. Splunk can make REST calls only its search peers. 

Forwarding _internal data is required also to see all logs from one place.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

scelikok
SplunkTrust
SplunkTrust

Hi @MLGSPLUNK,

MC is using REST calls to monitor Splunk Servers. That is why it should be able to access all Splunk Instances. Splunk can make REST calls only its search peers. 

Forwarding _internal data is required also to see all logs from one place.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

MLGSPLUNK
Path Finder

Thanks @scelikok for your fast answer, then it makes total sense for me, and learn something else.

So at the end:

- SH stablished as a search peer for the MC

- SH forward all its internals to idx cluster.

 

Ty.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...