Deployment Architecture

Distributed deployment and MC: Do I need to add SH if the SH is sending its data to IDX cluster?

MLGSPLUNK
Path Finder

Hi community.

Just preparing for my ARCH practical lab. I heard that it's mandatory to add to the MC the non clustered SH as a search peer. However, I already configured the SH to send its internal data to the IDX cluster I have deployed.

My question is: Do I need to also configure the SH as a search peer on the MC in order to be able to monitor it, or just with the cluster master as a search peer (it automatically adds all the clustered idx to the MC) will it do.

In theory if all the SH _internal data is at the IDX layer, the MC would take a look at the IDX cluster that contains the aleady forwarded _internal data from the SH, ritght?

Please provide an explanation so I can beat the practical lab. Thanks!

0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @MLGSPLUNK,

MC is using REST calls to monitor Splunk Servers. That is why it should be able to access all Splunk Instances. Splunk can make REST calls only its search peers. 

Forwarding _internal data is required also to see all logs from one place.

 

If this reply helps you an upvote is appreciated.

View solution in original post

scelikok
SplunkTrust
SplunkTrust

Hi @MLGSPLUNK,

MC is using REST calls to monitor Splunk Servers. That is why it should be able to access all Splunk Instances. Splunk can make REST calls only its search peers. 

Forwarding _internal data is required also to see all logs from one place.

 

If this reply helps you an upvote is appreciated.

MLGSPLUNK
Path Finder

Thanks @scelikok for your fast answer, then it makes total sense for me, and learn something else.

So at the end:

- SH stablished as a search peer for the MC

- SH forward all its internals to idx cluster.

 

Ty.

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...