Deployment Architecture

Turn non clustered indexers into clustered indexer

lucacaldiero
Path Finder

Hi all,

I have an architecture with a search head cluster (3 members) and and 2 indexers, that are not in cluster.

Which is the best way to turn the 2 indexers in a indexer cluster and then add it to the search head cluster?

 

Thanks in advance.

0 Karma

andrelucasmelo
Engager

Hi,

To create a new Indexer Cluster, you need a additional Splunk machine to use as Cluster Master.

You can use this documentation to configure a New Cluster Master.
https://docs.splunk.com/Documentation/Splunk/8.1.1/Indexer/ConfiguremanagerwithCLI

Notice that you can use only a max of 2 in Replication and Search Factor because you have only two Indexers.

Add your indexers to Cluster following this documentation:
https://docs.splunk.com/Documentation/Splunk/8.1.1/Indexer/ConfigurepeerswithCLI

The last step is add your Search Head Cluster nodes to Indexer Cluster using this documentation:
https://docs.splunk.com/Documentation/Splunk/8.1.1/DistSearch/SHCandindexercluster

*Consider that in an Indexer Cluster it is recommended to have at least 3 Indexers.

 

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk has a document for that.  See https://docs.splunk.com/Documentation/Splunk/8.1.1/Indexer/Migratenon-clusteredindexerstoaclusterede...

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...