Getting Data In

How to add more indexers to your existing indexer cluster?

joesrepsol
Path Finder

Not finding much on this subject, and looking for a little guidance...

I already have an indexer cluster up and running with (2) indexers in the cluster. Looking to add a new indexer to that pool. From reading it looks like I...

1) enter maintenance mode on the cluster master...
2) up the search factor/replication factor (if desired)...
3) enable indexer clustering on the new indexer and join the indexer to the master (peer node configuration)
4) ensure all indexes are recreated on the new indexer
5) Data rebalance
6) Bring master out of maintenance mode
7) Push out new outputs.conf to forwarders with 3rd indexer info as well
??

Joe

Splunk Enterprise 6.5.0

richgalloway
SplunkTrust
SplunkTrust

The process for adding an indexer to a cluster is documented at https://docs.splunk.com/Documentation/Splunk/8.0.1/Indexer/Addclusterpeer . The steps apply to earlier versions of Splunk, not just 8.0.1.

---
If this reply helps you, Karma would be appreciated.

maraman_splunk
Splunk Employee
Splunk Employee

Hello

1) install splunk the same way you did for other indexer and enable indexer clustering on the new indexer
-> the indexer join the cluster, get the index list, apps to be deployed on indexers, ... become a target for replication and search head learn that it exist.
2) Push out new outputs.conf to forwarders with 3rd indexer info as well
3) up the search factor/replication factor (if desired)...
4)if needed Data rebalance

0 Karma

khalidewaidah
Explorer

Dear All
I follow all steps above but the new indexers can't add is there any settings need to do in cm

0 Karma

martynoconnor
Communicator

If they can't add, are the definitely the same version as the other indexers? Are they the same operating system? Do they have the required ports open for replication and communication to the master? Is there a network route from them to the master and to the other peers? Is there a firewall that needs configured (both on the network and on the host). Are the new indexers using the correct pass4SymmKey? Is there a typo in the name of the clustermaster in server.conf [clustering] stanza?

As a troubleshooting measure, take a look at $SPLUNK_HOME/var/log/splunk/splunkd.log for WARN or ERROR messages concerning clustering on the new indexers. The reason why they can't join will likely be explained there.

Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...