Deployment Architecture

When new search peers can't be added to the indexer cluster due to administration issues, how do you add new search peers to the search head cluster?

vincenteous
Communicator

Hello Experts,

Currently, I have set up both the search head cluster and the indexer cluster in my production environment and all indexing and searching activities work perfectly. However, there are also standalone indexers outside of my environment which are handled by another team in a different network segment and are required to be added as search peers, but can't be added as indexer cluster members due to administration issues.

With this situation, can I just simply add those standalone indexers as search peers for my search head cluster from the GUI? Or is there another additional procedure to be added?

Thank you and please advise.

0 Karma
1 Solution

dkeck
Influencer

No, adding via GUI should work fine.

Note that you can let the Cluster replicate this for you, see:

http://docs.splunk.com/Documentation/Splunk/7.2.1/DistSearch/Connectclustersearchheadstosearchpeers#...

View solution in original post

0 Karma

dkeck
Influencer

No, adding via GUI should work fine.

Note that you can let the Cluster replicate this for you, see:

http://docs.splunk.com/Documentation/Splunk/7.2.1/DistSearch/Connectclustersearchheadstosearchpeers#...

0 Karma

vincenteous
Communicator

Noted. Thank you for your confirmation. I first thought that different types of search peers can't be configured together. Seems there's no issue to add manually.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...