Getting Data In

Can I add an Index-Cluster to a Multisite-Index-Cluster

pinVie
Path Finder

Hello all,

I currently have a quite big splunk infrastructure with a multisite cluster (5 sites) each site has two indexer server. Additionally I have a smaller site with a completely independent Splunk Setup - it consists of several forwarders, a search head and one index-cluster (two server as well).

Is there any possibility to add this single index-cluster into the multisite cluster (as site Nr. 6) without loosing any data ?

Thx a lot for your help!

0 Karma
1 Solution

mahamed_splunk
Splunk Employee
Splunk Employee

So you want to add the Site 6 to the existing multisite cluster ? Yes, you can do that. Keep in mind that the existing data in Site 6 will still remain in Site 6 and will not be replicated to other sites. Any new data you index in Site 6 will follow the site policies and get replicated to other sites

View solution in original post

mahamed_splunk
Splunk Employee
Splunk Employee

So you want to add the Site 6 to the existing multisite cluster ? Yes, you can do that. Keep in mind that the existing data in Site 6 will still remain in Site 6 and will not be replicated to other sites. Any new data you index in Site 6 will follow the site policies and get replicated to other sites

pinVie
Path Finder

Ok - thank you for this information. How would I do this ? Just remove the Cluster-Master for Site 6 and configure the "Multi-Site-Cluster-ClusterMaster" + the additional Multi-Site settings for the two indexers on site 6 ?

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

yes. Update the Site 6 indexers Cluster Master URI to point to Multisite Cluster Master URI and add site = site6 values. That's all.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...