Deployment Architecture

How to create indexes to be replicated in an indexer clustering environment?

Ahmedkhalil
Path Finder

Hi All,

I have configured indexer clustering in Splunk, but I don't know how to create indexes that are replicated in this cluster.

0 Karma
1 Solution

Steve_G_
Splunk Employee
Splunk Employee

This topic addresses in detail the issue of how to configure indexes in a cluster:

http://docs.splunk.com/Documentation/Splunk/6.3.1/Indexer/Configurethepeerindexes

View solution in original post

Steve_G_
Splunk Employee
Splunk Employee

This topic addresses in detail the issue of how to configure indexes in a cluster:

http://docs.splunk.com/Documentation/Splunk/6.3.1/Indexer/Configurethepeerindexes

john_glasscock
Path Finder

Trying to follow the document.... which file do you have to manually update with the new index?

Splunkhome/etc/master-apps/_cluster/local/(server.conf) sorry I ment indexes.conf on the master node?

Then reapply the cluster?

0 Karma

Steve_G_
Splunk Employee
Splunk Employee

You create indexes in indexes.conf, not server.conf. You update the file on the master node and then use the CLI command 'splunk apply cluster-bundle' to deploy the updates to the peer nodes.

For details on updating configurations via that command, see: http://docs.splunk.com/Documentation/Splunk/6.3.1/Indexer/Updatepeerconfigurations

(referenced from the 'configure peer indexes' topic as well)

0 Karma

Ahmedkhalil
Path Finder

Ok thank you so much 🙂

0 Karma

john_glasscock
Path Finder

Sorry, I was asking Steve G., I am having the same issue. I have added the indexes there and it pushes out the other indexes, but does not show on the deployment server under indexing cluster page.

0 Karma

Ahmedkhalil
Path Finder

as i read from document you have first to send data to newly created indexes in order to see them

0 Karma

Steve_G_
Splunk Employee
Splunk Employee
0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...