Deployment Architecture

Forward data to indexer cluster

RanjithaN99
Explorer

Hi,

I am working in a distributed Splunk environment with one search head and an indexer cluster.

I am trying to monitor a path that is on the search head and I created a monitor input from the web GUI.

How do I create an index on the indexer cluster and configure forwarding from the search head to the indexer cluster.

Please help me.

Thanks 

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @RanjithaN99,

Indexer Cluster is managed by the Cluster Manager so you have to create the new indexes.conf in this server that deploys it to the indexers; for more infos see at https://docs.splunk.com/Documentation/Splunk/9.2.0/Indexer/Aboutclusters

in few words, you have to create a stanza in indexes.conf with the new index using the CLI and push the configuration using GUI.

For data forwarding from te SH to the Indexers, you should already have this configuration because it's a best practice to send internal logs from all the Splunk servers to Indexers.

If not go in [Settings > Forwarding and Receiving > Forwarding] and configure Forwarding.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...