Deployment Architecture

When new search peers can't be added to the indexer cluster due to administration issues, how do you add new search peers to the search head cluster?

vincenteous
Communicator

Hello Experts,

Currently, I have set up both the search head cluster and the indexer cluster in my production environment and all indexing and searching activities work perfectly. However, there are also standalone indexers outside of my environment which are handled by another team in a different network segment and are required to be added as search peers, but can't be added as indexer cluster members due to administration issues.

With this situation, can I just simply add those standalone indexers as search peers for my search head cluster from the GUI? Or is there another additional procedure to be added?

Thank you and please advise.

0 Karma
1 Solution

dkeck
Influencer

No, adding via GUI should work fine.

Note that you can let the Cluster replicate this for you, see:

http://docs.splunk.com/Documentation/Splunk/7.2.1/DistSearch/Connectclustersearchheadstosearchpeers#...

View solution in original post

0 Karma

dkeck
Influencer

No, adding via GUI should work fine.

Note that you can let the Cluster replicate this for you, see:

http://docs.splunk.com/Documentation/Splunk/7.2.1/DistSearch/Connectclustersearchheadstosearchpeers#...

0 Karma

vincenteous
Communicator

Noted. Thank you for your confirmation. I first thought that different types of search peers can't be configured together. Seems there's no issue to add manually.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...