Deployment Architecture

How to create a new index in an index cluster?

Payne1882
Engager

I have 1 Master, 1 Search Head and 3 Index peers in my cluster.

What is the Correct process for creating new indexes?

I understand I can create the indexes.conf file on the master in master-apps/_cluster and push out using configuration bundle. This came back successful. But if I go to "Settings > Indexes" then I cannot see my new index that I specified in the indexes.conf file.

Have I missed something in the UI?

I cannot see the Db directory's that are created for the buckets which I specified in the indexes.conf file.

1 Solution

richgalloway
SplunkTrust
SplunkTrust

You have the right procedure for adding an index to your indexers. To make the index visible to your search head, you must also copy indexes.conf from the Master Node to the SH. Restart or refresh (https://yourhost:8000/en-US/debug/refresh) the SH to apply the change.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

pradeepkumarg
Influencer

On which instance are you checking the settings? You should check on the peer and not the master.
You can also check the "index clusterting" page on the master if you enabled the replication for that index.

 repFactor = auto 

0 Karma

shashi12345678
Engager

I'm facing the same issue, I have created new index under /opt/splunk/etc/master-apps/_cluster/local. on master node
Indexes.conf
[test]
disabled = false
repFactor = auto
homePath = $SPLUNK_DB/test/db
coldPath = $SPLUNK_DB/test/colddb
thawedPath = $SPLUNK_DB/test/thaweddb
tstatsHomePath = volume:_splunk_summaries/test/datamodel_summary
maxMemMB = 20
maxConcurrentOptimizes = 6
maxHotIdleSecs = 86400
maxHotBuckets = 10
maxDataSize = auto_high_volume

and I was able to see the index on all 3-peers from backend, but couldn't the index from any peer UI and also was unable to index any data to that index (test)

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You have the right procedure for adding an index to your indexers. To make the index visible to your search head, you must also copy indexes.conf from the Master Node to the SH. Restart or refresh (https://yourhost:8000/en-US/debug/refresh) the SH to apply the change.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Jarohnimo
Builder

I downvoted this post because wrong!

0 Karma

Prakash493
Communicator

Hi , i am also in the same situation , i create the indexes in master-apps and push it out successfully , my concern is we are using search head cluster with a search head deployer to push the apps , do i need to copy my indexes.conf to each of the search heads too if so only search head or in search head deployer too. in which location of search head i need to copy and paster the indexes.conf

0 Karma

risgupta
Path Finder

No it is not required to push the indexes config to search heads

ddrillic
Ultra Champion

@Payne1882, keep in mind that you can see the indexes on the file systems of the indexers and via the UI of the indexers. And usually you don't need the indexes to be visible in the UI of the SHs, unless, for example, you upload data via the UI to a specific index...

0 Karma

Payne1882
Engager

Thank you for your help guys, this has cleared it up for me.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...