Hello I am having Splunk Enterprise 6.5.1. Now there is a task to add 2 more indexers to the Indexer cluster(6 Indexers).
Please guide me on the same. I read few posts and documentation, so before proceeding I wanted to clear few doubts as listed below:
Also detailed steps on the same will be definitely helpful for me and others. Thank you.
1) Search Factor and Replication Factor are business rules and depend on your storage and data velocity. If you keep 3/2 then you can lose at-most 3 indexers
2) Yes, you need to add the new indexers to outputs.conf
. Easy to do if you have an app dedicated to outputs
3) The forwarders should already have deploymentclient.conf
if your using the deployment server. You do NOT put deploymentclient.conf
on the indexers, but rather make the cluster master a deployment client, deploy your configs there and push it to your search peers.
4) You gotta enable distributed mode and join it to the cluster master
http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/UsetheCLI
5) The indexers will rebalance on their own when you join them to the cluster
1) Search Factor and Replication Factor are business rules and depend on your storage and data velocity. If you keep 3/2 then you can lose at-most 3 indexers
2) Yes, you need to add the new indexers to outputs.conf
. Easy to do if you have an app dedicated to outputs
3) The forwarders should already have deploymentclient.conf
if your using the deployment server. You do NOT put deploymentclient.conf
on the indexers, but rather make the cluster master a deployment client, deploy your configs there and push it to your search peers.
4) You gotta enable distributed mode and join it to the cluster master
http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/UsetheCLI
5) The indexers will rebalance on their own when you join them to the cluster
Hi @skoelpin ,
Do we need to keep the cluster in maintenance mode if we want to add a new indexer to the cluster ?