Deployment Architecture

Splunk Deployment

himapate
Explorer

Hi ,

We are deploying Splunk in our environment and have been stuck up at a point.

We have deployed Indexer cluster in one network it consist of the following details
2 search head
4 indexer
Master node
Deployment server

Now our requirement is that we want to integrate one indexer present at a different site and network with the search head of the current cluster.

Is it possible and if so how can it be done ?

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

To integrate the other indexer in the search head you have only to insert it in the search peers list of each search head.
if you want to insert it also in the indexer cluster you have to follow the related procedure you already used for the other indexers.
remember that the old logs cannot be replicated.
bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

To integrate the other indexer in the search head you have only to insert it in the search peers list of each search head.
if you want to insert it also in the indexer cluster you have to follow the related procedure you already used for the other indexers.
remember that the old logs cannot be replicated.
bye.
Giuseppe

0 Karma

himapate
Explorer

Hi ,

Thanks for your response, the solution provided seems to be helpful.However had a doubt regarding the license.
The separate indexer has its own license and my cluster has a different license would that seem to be clashing or would be working respectively.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Every Indexer uses own license, There aren't restrictions for the Search Heads.
In this way you can search logs from the same Search Heads both on the cluster and the separate Indexer.
Bye.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...