Getting Data In

Add new indexers to existing indexer cluster

vicky05ssr04
Engager

Hello I am having Splunk Enterprise 6.5.1. Now there is a task to add 2 more indexers to the Indexer cluster(6 Indexers).
Please guide me on the same. I read few posts and documentation, so before proceeding I wanted to clear few doubts as listed below:

  1. Do I need to touch the SearchFactor & ReplicationFactor (currently SF is 2 and RF is 3). If yes, then how to calculate it.
  2. Probably I need to add the indexer details in the outputs.conf
  3. Referring to Apps(outputs.conf). We have deployment server in place, so is there a need for deploymentclient.conf in the 2 new indexers and do I need to add the indexers details in the serverclass.conf.
  4. How to enable indexer clustering on the new indexer and join the indexer to the master (peer node configuration). what are the exact steps for configuring.
  5. Couple of Indexes exists in the current Indexers, so do I need to enable anything to make the Indexes balanced across new indexers as well.

Also detailed steps on the same will be definitely helpful for me and others. Thank you.

1 Solution

skoelpin
SplunkTrust
SplunkTrust

1) Search Factor and Replication Factor are business rules and depend on your storage and data velocity. If you keep 3/2 then you can lose at-most 3 indexers

2) Yes, you need to add the new indexers to outputs.conf. Easy to do if you have an app dedicated to outputs

3) The forwarders should already have deploymentclient.conf if your using the deployment server. You do NOT put deploymentclient.conf on the indexers, but rather make the cluster master a deployment client, deploy your configs there and push it to your search peers.

4) You gotta enable distributed mode and join it to the cluster master
http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/UsetheCLI

5) The indexers will rebalance on their own when you join them to the cluster

View solution in original post

skoelpin
SplunkTrust
SplunkTrust

1) Search Factor and Replication Factor are business rules and depend on your storage and data velocity. If you keep 3/2 then you can lose at-most 3 indexers

2) Yes, you need to add the new indexers to outputs.conf. Easy to do if you have an app dedicated to outputs

3) The forwarders should already have deploymentclient.conf if your using the deployment server. You do NOT put deploymentclient.conf on the indexers, but rather make the cluster master a deployment client, deploy your configs there and push it to your search peers.

4) You gotta enable distributed mode and join it to the cluster master
http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/UsetheCLI

5) The indexers will rebalance on their own when you join them to the cluster

nawazns5038
Builder

Hi @skoelpin ,

Do we need to keep the cluster in maintenance mode if we want to add a new indexer to the cluster ?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...