i am installing two new indexers for test, as test indexers they have very small disks.
As clustermember they get indexes.conf from the cluster-bundle, where _internal is set to keep logs for a year.
_internal configuration is made for my production splunk servers, how can i bypass the cluster bundle on the tests servers ?
Hi Ed_alias, If your cluster apps are defining indexes in default only, I believe that you could put config into $SPLUNKHOME/etc/system/local/indexes.conf to override anything the cluster master puts out, but you'll want to be very careful about this. See : http://docs.splunk.com/Documentation/Splunk/6.1/admin/Wheretofindtheconfigurationfiles for more info on config precedence.
Alternatively, you could not add the indexers to the cluster, and leave them as independent indexers.
Let me know if this helps! 😄