Deployment Architecture

Why do all searches execute from cluster member at site 1 in scheduled searches in a Multi Site Cluster?

kwoodrgews
New Member

I am working on a Splunk Deployment with a cluster of search heads spanning two physical sites.  At Site1 there is actually only one search head.  At Site2 there are two search heads.

The load balancer managing Splunk Web access tends to favor Site1 and so almost all users end up landing on the sole search head at Site1 when they access our Splunk Web url.

What I have noticed, however, is that the search head at Site1 also seems to run almost all of the scheduled searches.  Also, because it is favored by the load balancer for user access, users log into that search head and it takes on most of the ad-hoc searches.

I know that this setup is very non-optimal, and as the story goes, this is a mess I inherited recently in taking over Splunk responsibilities.  More search heads are needed actually at both physical Sites, but in the meantime, I am trying to understand why the cluster captain is not more evenly distributing the saved searches, alerts, reports, etc.  Why do they all seem to execute from the sole cluster member at Site1?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...