Getting Data In

2 Indexer and Summary

erick_costa
Path Finder

Hi,

          I have 2 Indexer and 1 SearchHead. Where should the data from my summary of the SH or the Indexer? 

I checked and in my case they are in HS. Is this correct? I do not think anything in the documentation about this.

Regards,

Erick Eduardo

0 Karma

Ayn
Legend

Well it depends. It's not a matter of what is 'correct' - if you want the summarized data to reside on the search head, that's fine. If you want your indexers to have all data, you need to configure your search head to forward the summary events to your indexers. This is a very common question, here are some previous questions and corresponding answers:
http://answers.splunk.com/answers/5837/summary-indexing-on-a-search-head
http://answers.splunk.com/answers/39314/how-do-you-handle-summary-indexing-in-a-distributed-environm...
http://answers.splunk.com/answers/69365/forwarding-summary-index-from-search-head-to-indexer

erick_costa
Path Finder

If I send my summary to the indexers, improve the performance of search?

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...