- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
dstuder
Communicator
11-05-2021
03:45 PM
I've got my universal forwarders and heavy forwarders doing indexer discovery through the cluster master like so ...
**************************
* outputs.conf *
**************************
[indexer_discovery:clustermaster]
pass4SymmKey = {password}
master_uri = https://{my cluster master}.domain.foo:8089
[tcpout:clustermastergroup]
indexerDiscovery = clustermaster
useACK = true
[tcpout]
defaultGroup = clustermastergroup
Is there any reason I could not do the same in the cluster master's outputs.conf file? Basically, it would ask itself over 8098 who the peer nodes are.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
isoutamo
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
SplunkTrust
11-05-2021
04:10 PM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
isoutamo
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
SplunkTrust
11-05-2021
04:10 PM
if you are using it for clients then you should use it also for CM.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
dstuder
Communicator
11-09-2021
08:30 AM
I did apply the outputs.conf config to the cluster master and indeed it did work just fine.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/3ea3a/3ea3a1ee145bc049c3683bb30611a52a69c9b108" alt="a_kearney a_kearney"
a_kearney
Path Finder
11-16-2021
04:03 AM
For the master_uri configuration did you use the same value as for the Forwarders or did you use the loopback interface address (e.g. https://127.0.0.1:8089)?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
dstuder
Communicator
11-16-2021
08:17 AM
I used the DNS entry for simplicity sake so that all the machines are set up the same way.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
isoutamo
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
SplunkTrust
11-16-2021
11:14 AM
My personal advice is: use always dns names, never ips. That way it’s much easier to do changes later on.
data:image/s3,"s3://crabby-images/5d9f8/5d9f80c54160124d38856b77a799077db7d57026" alt=""