Deployment Architecture

If I am using a custom index, do we need to create this index on each and every peer in an indexer cluster?

saifuddin9122
Path Finder

Hello,

I am new to Splunk.

I am trying to deploy an indexer cluster (single-site) as the diagram in the docs suggest that we need to connect every forwarder to each and every single peer in the cluster. My question is, if am using my custom index (ExampleIndex), do I need to create this index on every peer node (either using WEB OR INDEXES>CONF) or no need of creating index on every peer node??

Thanks,
SK

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Yes, but you do it using the configuration bundle aka "cluster bundle" instead:

http://docs.splunk.com/Documentation/Splunk/6.0/Indexer/Updatepeerconfigurations

The cluster bundle will contain an indexes.conf and it will distribute out from the index/peer master.

View solution in original post

jkat54
SplunkTrust
SplunkTrust

Yes, but you do it using the configuration bundle aka "cluster bundle" instead:

http://docs.splunk.com/Documentation/Splunk/6.0/Indexer/Updatepeerconfigurations

The cluster bundle will contain an indexes.conf and it will distribute out from the index/peer master.

jkat54
SplunkTrust
SplunkTrust

You know technically you don't have to create it on every indexer/peer but then you can't use the replication and benefits of the cluster.

I also didn't mention that you have to put a setting in the indexes.conf to make it replicates across the peers.

It's called repFactor and usually you set it equal to auto:

repFactor=auto

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...