Deployment Architecture

Need help in Replication.

vikcee
Path Finder

Hello All,

I have created a Indexer cluster. In my master indexer I created one Index and added some data (/etc/master-app/_cluster/local). and pushed the index to all the peers. Index is replicated in all the indexer But data is showing in only master index. Now I want to add some data to all my indexer. What should I do?

Thanks
Vikash Gupta

0 Karma
1 Solution

woodcock
Esteemed Legend

There is no such thing as a Master Indexer. You should have a created an app inside of master-apps on the Cluster Master that contains an indexes.conf file. DO NOT create any splunk configuration files for this directly on any indexers. Then push out the indexes.conf app (which has the file) using the cluster commands on the Cluster Master. This will cause a rolling restart on the Indexers once they receive the new configurations, after which you will be able to send data to the new index on the indexers.

View solution in original post

0 Karma

woodcock
Esteemed Legend

There is no such thing as a Master Indexer. You should have a created an app inside of master-apps on the Cluster Master that contains an indexes.conf file. DO NOT create any splunk configuration files for this directly on any indexers. Then push out the indexes.conf app (which has the file) using the cluster commands on the Cluster Master. This will cause a rolling restart on the Indexers once they receive the new configurations, after which you will be able to send data to the new index on the indexers.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

We may have a terminology problem. There is no such thing as a "master indexer". The instance in charge of an indexer cluster is the "Master Node" or "Cluster Master". A clustered indexer cannot serve as the Master.
Defining an index on the Master Node (MN) and pushing the configuration to the peers will define that index on all indexers.
All of your Splunk instances should be forwarding their output to the indexers. Not only does that make all Splunk logs searchable, but it also means data added on the MN or a Search Head will be sent to the indexers and replicated properly.

---
If this reply helps you, Karma would be appreciated.
0 Karma

p_gurav
Champion

Could you share the indexes.conf? Also, on which Splunk instance wrote your inputs.conf?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...