Getting Data In

How to add an index to a search head and keep it separate from other search heads?

Log_wrangler
Builder

Hello,

I have a search head that communicates with 3 non-clustered indexers ( autolb distribution of data). Indexed data is distributed evenly across all three indexers.

Now I need to add a remote indexer to the search head but I don't want to add it to the other indexers group. It needs to be separate because the remote indexer is managed by someone else. However I need it to communicate to my search head so I can monitor the data contained in that remote indexer.

How would I set this up?

Thank you

0 Karma
1 Solution

lakshman239
Influencer

I assume, you want your search head to 'search' the data/logs in the newly added indexer. If so, you can add that just like the other indexers via dist search

https://docs.splunk.com/Documentation/Splunk/7.2.4/DistSearch/Configuredistributedsearch

https://docs.splunk.com/Documentation/Splunk/7.2.4/Admin/Distsearchconf

On the forwarder level, where you define tcpout group, you can decide what logs/data needs to go to new indexer or the old indexers [ 3 non-clustered one].

Do you see any issues with this approach?

View solution in original post

0 Karma

lakshman239
Influencer

I assume, you want your search head to 'search' the data/logs in the newly added indexer. If so, you can add that just like the other indexers via dist search

https://docs.splunk.com/Documentation/Splunk/7.2.4/DistSearch/Configuredistributedsearch

https://docs.splunk.com/Documentation/Splunk/7.2.4/Admin/Distsearchconf

On the forwarder level, where you define tcpout group, you can decide what logs/data needs to go to new indexer or the old indexers [ 3 non-clustered one].

Do you see any issues with this approach?

0 Karma

Log_wrangler
Builder

Thank you, I guess in my environment I just need to add the indexer as a "search peer" just wanted to make sure that something was not accidentally created where the remote indexer was auto added/joined to the others in an autolb fashion. But it does not.

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...