Deployment Architecture

Under what configuration file and stanza do I configure CMConfig - multisite=[true|false]?

dave_maclean
Explorer

Every 5 seconds on my deployment server (in a clustered environment), I get this in splunkd.log:

WARN CMConfig - multisite=[true|false] missing from this stanza. Assuming this isn't multisite

I realize it's not a problem per se, but I'd like to add 'multisite = false' in the appropriate stanza in the appropriate config file. I tried adding the following to the $SPLUNK_HOME/etc/system/local/server.conf:

[clustering]
multisite = false

but that didn't help. Any suggestions please? Wait for 6.2? Note: my Cluster Master is a separate server, and it does not display this message in its splunkd.log.

_smp_
Builder

I was getting this error on my 7.1.7 Search Head cluster, which is connected to multiple index clusters. I was able to eliminate it by editing server.conf:

[clustermaster:<label>]
multisite = false
0 Karma

rolszewski
New Member

Neither of these solutions solved my problem, however this link showed that I should put the multisite = false in the clustermaster:somesite stanza

https://docs.splunk.com/Documentation/Splunk/7.2.5/Indexer/Configuremulti-clustersearch

0 Karma

woodcock
Esteemed Legend

I got this error when I added site=site1 but did not restart my Search Head. Try a restart and it should work.

0 Karma

dxu_splunk
Splunk Employee
Splunk Employee

any luck w

[general]
site = default

(default if ur not using multisite)

I remember this was a typo for searchheads (they would complain about 'multisite' but what they meant to complain about was 'site')

0 Karma

hortonew
Builder

I just tried doing this and it didn't help.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...