Getting Data In

2 Indexer and Summary

erick_costa
Path Finder

Hi,

          I have 2 Indexer and 1 SearchHead. Where should the data from my summary of the SH or the Indexer? 

I checked and in my case they are in HS. Is this correct? I do not think anything in the documentation about this.

Regards,

Erick Eduardo

0 Karma

Ayn
Legend

Well it depends. It's not a matter of what is 'correct' - if you want the summarized data to reside on the search head, that's fine. If you want your indexers to have all data, you need to configure your search head to forward the summary events to your indexers. This is a very common question, here are some previous questions and corresponding answers:
http://answers.splunk.com/answers/5837/summary-indexing-on-a-search-head
http://answers.splunk.com/answers/39314/how-do-you-handle-summary-indexing-in-a-distributed-environm...
http://answers.splunk.com/answers/69365/forwarding-summary-index-from-search-head-to-indexer

erick_costa
Path Finder

If I send my summary to the indexers, improve the performance of search?

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...