I currently have a quite big splunk infrastructure with a multisite cluster (5 sites) each site has two indexer server. Additionally I have a smaller site with a completely independent Splunk Setup - it consists of several forwarders, a search head and one index-cluster (two server as well).
Is there any possibility to add this single index-cluster into the multisite cluster (as site Nr. 6) without loosing any data ?
Thx a lot for your help!
So you want to add the Site 6 to the existing multisite cluster ? Yes, you can do that. Keep in mind that the existing data in Site 6 will still remain in Site 6 and will not be replicated to other sites. Any new data you index in Site 6 will follow the site policies and get replicated to other sites
Ok - thank you for this information. How would I do this ? Just remove the Cluster-Master for Site 6 and configure the "Multi-Site-Cluster-ClusterMaster" + the additional Multi-Site settings for the two indexers on site 6 ?
yes. Update the Site 6 indexers Cluster Master URI to point to Multisite Cluster Master URI and add site = site6 values. That's all.