I recently deployed a search head cluster and indexer cluster and integrated.
How I can disable indexing on search head cluster members? Is there any workaround without making an entry in outputs.conf?
You can disable indexing and forward the data to indexers from search head.
[indexAndForward] index = [true|false] * If set to true, data is indexed. * If set to false, data is not indexed. * Default depends on whether the Splunk instance is configured as a forwarder, modified by any value configured for the indexAndForward attribute in [tcpout].
You can do it also using web interface:
Settings -- Forwarder and Receiving -- Configure Forward
I don't want to index data from SHC neither on SH nor on other Indexers. I will monitor SHC from other monitoring tools.
Even though you don't want any monitoring data, it's highly suggested to forward the internal logs at least since it contain a lot of metrics which will help you in troubleshooting
Agree with renjith.nair for a good practice.
Monitoring SH by other monitoring tool is most likely different from keeping logs of splunk instance for logging behavior of Splunk instance including splunkweb, kvstore, splunkd etc. So, you cannot really monitor Splunk SH in SHC making use of DMC feature without indexing such logs. You cannot create useful correlation searches etc. Anyway, that's an interesting reason.