Deployment Architecture

There is no "search head clustering" below "settings" in my SH cluster member's web

danielwan
Explorer

I have built an SH cluster and an indexer cluster with Splunk 6.5.4 . I would like to monitor SH cluster via Splunk web.

I followed the following document (I note it's a Splunk 7.0 document)

http://docs.splunk.com/Documentation/Splunk/7.0.1/DistSearch/SHCsettings

But below DISTRIBUTED ENVIRONMENT of settings on my SH captain (a static captain than dynamic captain), there is no "search head clustering" at all, instead, there are 3 menu items, which are Indexer clustering, Forwarder management and Distributed search.

I can list my SH cluster details properly via CLI, e.g. splunk show shcluster-status and splunk list shcluster-members.

Is monitoring SH cluster via Splunk web available in Splunk 6.5? How to enable it?

0 Karma

adonio
Ultra Champion

hello there,

the only GUI indication that you have a SHC is that the settings menu is not full (although you can click on an icon that will enable it)
also, if using a load balancer, your url will be different then the host you are on (help button and then about button)
not sure what do you mean by monitoring the SHC but if you would like to see metrics about replication, long searches and SHC health, use the MC (Splunk monitoring console)

hope it helps

0 Karma

danielwan
Explorer

I have clicked "show all menus", I also walked through my SH captain and SH peer one by one, only saw Distributed search but not Search Head Clustering in the menu.

Yes, I want to monitor SHC metrics. Splunk web would be much easier than CLI.

My SH does not have MC(Splunk monitoring console), only indexer cluster member has MC.

How to enable MC on SH member?

0 Karma

adonio
Ultra Champion

add your SHC Members and Deployer to the MC
link:
http://docs.splunk.com/Documentation/Splunk/7.0.1/DMC/Configureindistributedmode
here is the full description of views and functions out of the box (MC)
http://docs.splunk.com/Documentation/Splunk/7.0.1/DMC/SHCdashboards

hope it helps

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...