Getting Data In

Can I add an Index-Cluster to a Multisite-Index-Cluster

pinVie
Path Finder

Hello all,

I currently have a quite big splunk infrastructure with a multisite cluster (5 sites) each site has two indexer server. Additionally I have a smaller site with a completely independent Splunk Setup - it consists of several forwarders, a search head and one index-cluster (two server as well).

Is there any possibility to add this single index-cluster into the multisite cluster (as site Nr. 6) without loosing any data ?

Thx a lot for your help!

0 Karma
1 Solution

mahamed_splunk
Splunk Employee
Splunk Employee

So you want to add the Site 6 to the existing multisite cluster ? Yes, you can do that. Keep in mind that the existing data in Site 6 will still remain in Site 6 and will not be replicated to other sites. Any new data you index in Site 6 will follow the site policies and get replicated to other sites

View solution in original post

mahamed_splunk
Splunk Employee
Splunk Employee

So you want to add the Site 6 to the existing multisite cluster ? Yes, you can do that. Keep in mind that the existing data in Site 6 will still remain in Site 6 and will not be replicated to other sites. Any new data you index in Site 6 will follow the site policies and get replicated to other sites

pinVie
Path Finder

Ok - thank you for this information. How would I do this ? Just remove the Cluster-Master for Site 6 and configure the "Multi-Site-Cluster-ClusterMaster" + the additional Multi-Site settings for the two indexers on site 6 ?

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

yes. Update the Site 6 indexers Cluster Master URI to point to Multisite Cluster Master URI and add site = site6 values. That's all.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...