Getting Data In

App/Add-on

BRFZ
Communicator

Hello,

I have an architecture with a single SH and two indexers. I've installed the Splunk for Microsoft 365 add-on on the search head, so the collected logs are stored in the search head's index, but I want them to be stored on the indexers. Can you help me?

Thank you.

Labels (2)
0 Karma

BRFZ
Communicator

@PaulPanther Thank you for your response, and does it not have any impact given that the indexers are not in a cluster?

0 Karma

PaulPanther
Motivator

@BRFZ  If you have no cluster the data are not replicated. So if one indexer goes down your search couldn't access all data.

0 Karma

PaulPanther
Motivator

1. Create the neccessary indexes on your indexer

2. Configure Best practice: Forward search head data to the indexer layer - Splunk Documentation

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...