Getting Data In

2 Indexer and Summary

erick_costa
Path Finder

Hi,

          I have 2 Indexer and 1 SearchHead. Where should the data from my summary of the SH or the Indexer? 

I checked and in my case they are in HS. Is this correct? I do not think anything in the documentation about this.

Regards,

Erick Eduardo

0 Karma

Ayn
Legend

Well it depends. It's not a matter of what is 'correct' - if you want the summarized data to reside on the search head, that's fine. If you want your indexers to have all data, you need to configure your search head to forward the summary events to your indexers. This is a very common question, here are some previous questions and corresponding answers:
http://answers.splunk.com/answers/5837/summary-indexing-on-a-search-head
http://answers.splunk.com/answers/39314/how-do-you-handle-summary-indexing-in-a-distributed-environm...
http://answers.splunk.com/answers/69365/forwarding-summary-index-from-search-head-to-indexer

erick_costa
Path Finder

If I send my summary to the indexers, improve the performance of search?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...