Deployment Architecture

How to add a new index to a cluster

johnnythomson
Engager

Hi I am new to setting up clusters and setting up a new cluster so apologies in advance if this is a simple question.

I would like to setup several new indexes on the cluster to prior to setting up the forwarders that will be be used for getting the data into the cluster.

From the documentation it looks like I should configure the indexes.conf file on the master and push to the peers but i am not sure of the exact location of the indexes.conf file or the contents of the file for the peer setup.

Should place the new indexes.conf file in /_cluster/local ?

$SPLUNK_HOME/etc/master-apps
/_cluster
/default
/local
/
/
...

Please may i have an example of a indexes.conf file for a new syslog index example something like tcp port 8100 its a for a cluster and its location?

Thanks in advance

John

0 Karma

Steve_G_
Splunk Employee
Splunk Employee

echalex
Builder

Hi,

Old question, but I'm answering in case somebody finds this question, just as I did:

The idea apparently is to keep a common set of indexes centrally managed on the master, i.e. keep indexes.conf in a bundle that you distribute to the peers from etc/master-apps.

Another way of doing it could be through the deployment server, but apparently the master apps is recommended.

Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...