Getting Data In

Can you help me with an issue when adding a second indexer?

xindeNokia
Path Finder

one Search head / one indexer system — try to add a second indexer.

After I added the second indexer, in the search head (SH) — search peers page, it shows the newly added box state is up, but under the SH's monitor console, it still only shows one indexer.

Question:

How do you set the new search peer as the second indexer so that we can use one SH to search data from both indexers?

Any help is appreciated here.

Thanks!

0 Karma
1 Solution

ragedsparrow
Contributor

Can you search the data from the 2nd indexer on the Search Head?

For the Monitoring Console, you will have to go to Settings -> General Setup and add the Indexer Server Role for the new indexer. Then it should start showing up in the dashboards.

View solution in original post

0 Karma

ragedsparrow
Contributor

Can you search the data from the 2nd indexer on the Search Head?

For the Monitoring Console, you will have to go to Settings -> General Setup and add the Indexer Server Role for the new indexer. Then it should start showing up in the dashboards.

0 Karma

xindeNokia
Path Finder

Thank you for the quick answer! I found the general setup tab and it is working now. 🙂

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...