- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
App/Add-on
BRFZ
Communicator
03-26-2024
01:40 AM
Hello,
I have an architecture with a single SH and two indexers. I've installed the Splunk for Microsoft 365 add-on on the search head, so the collected logs are stored in the search head's index, but I want them to be stored on the indexers. Can you help me?
Thank you.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
BRFZ
Communicator
03-26-2024
02:00 AM
@PaulPanther Thank you for your response, and does it not have any impact given that the indexers are not in a cluster?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PaulPanther
Motivator
03-26-2024
02:07 AM
@BRFZ If you have no cluster the data are not replicated. So if one indexer goes down your search couldn't access all data.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PaulPanther
Motivator
03-26-2024
01:57 AM
1. Create the neccessary indexes on your indexer
2. Configure Best practice: Forward search head data to the indexer layer - Splunk Documentation
