Deployment Architecture

Indexer Discovery on Heavy Forwarder

kevingunn
New Member

Is it possible to enable indexerDiscovery on a Heavy Forwarder? I followed instructions here (http://docs.splunk.com/Documentation/Splunk/6.6.2/Indexer/indexerdiscovery), but haven't been able to get it to work. If I check https://localhost:8000/services/server/info on a heavy forwarder, it just lists the server role as kv_store, which to me tells me the indexerDiscovery is not working. If I manually add indexer peers as a forwarder server, the server role is correctly updated to reflect heavyweight_forwarder.

I don't see anything in the logs that points to any issues. Is there a way to check the status of a heavy forwarder or the status of indexer discovery (IE: list indexers that were discovered)?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...