Deployment Architecture

Turn non clustered indexers into clustered indexer

lucacaldiero
Path Finder

Hi all,

I have an architecture with a search head cluster (3 members) and and 2 indexers, that are not in cluster.

Which is the best way to turn the 2 indexers in a indexer cluster and then add it to the search head cluster?

 

Thanks in advance.

0 Karma

andrelucasmelo
Engager

Hi,

To create a new Indexer Cluster, you need a additional Splunk machine to use as Cluster Master.

You can use this documentation to configure a New Cluster Master.
https://docs.splunk.com/Documentation/Splunk/8.1.1/Indexer/ConfiguremanagerwithCLI

Notice that you can use only a max of 2 in Replication and Search Factor because you have only two Indexers.

Add your indexers to Cluster following this documentation:
https://docs.splunk.com/Documentation/Splunk/8.1.1/Indexer/ConfigurepeerswithCLI

The last step is add your Search Head Cluster nodes to Indexer Cluster using this documentation:
https://docs.splunk.com/Documentation/Splunk/8.1.1/DistSearch/SHCandindexercluster

*Consider that in an Indexer Cluster it is recommended to have at least 3 Indexers.

 

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk has a document for that.  See https://docs.splunk.com/Documentation/Splunk/8.1.1/Indexer/Migratenon-clusteredindexerstoaclusterede...

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...