Getting Data In

How to add more indexers to your existing indexer cluster?

joesrepsol
Path Finder

Not finding much on this subject, and looking for a little guidance...

I already have an indexer cluster up and running with (2) indexers in the cluster. Looking to add a new indexer to that pool. From reading it looks like I...

1) enter maintenance mode on the cluster master...
2) up the search factor/replication factor (if desired)...
3) enable indexer clustering on the new indexer and join the indexer to the master (peer node configuration)
4) ensure all indexes are recreated on the new indexer
5) Data rebalance
6) Bring master out of maintenance mode
7) Push out new outputs.conf to forwarders with 3rd indexer info as well
??

Joe

Splunk Enterprise 6.5.0

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The process for adding an indexer to a cluster is documented at https://docs.splunk.com/Documentation/Splunk/8.0.1/Indexer/Addclusterpeer . The steps apply to earlier versions of Splunk, not just 8.0.1.

---
If this reply helps you, Karma would be appreciated.

maraman_splunk
Splunk Employee
Splunk Employee

Hello

1) install splunk the same way you did for other indexer and enable indexer clustering on the new indexer
-> the indexer join the cluster, get the index list, apps to be deployed on indexers, ... become a target for replication and search head learn that it exist.
2) Push out new outputs.conf to forwarders with 3rd indexer info as well
3) up the search factor/replication factor (if desired)...
4)if needed Data rebalance

0 Karma

khalidewaidah
Explorer

Dear All
I follow all steps above but the new indexers can't add is there any settings need to do in cm

0 Karma

martynoconnor
Communicator

If they can't add, are the definitely the same version as the other indexers? Are they the same operating system? Do they have the required ports open for replication and communication to the master? Is there a network route from them to the master and to the other peers? Is there a firewall that needs configured (both on the network and on the host). Are the new indexers using the correct pass4SymmKey? Is there a typo in the name of the clustermaster in server.conf [clustering] stanza?

As a troubleshooting measure, take a look at $SPLUNK_HOME/var/log/splunk/splunkd.log for WARN or ERROR messages concerning clustering on the new indexers. The reason why they can't join will likely be explained there.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...