Getting Data In

I added a third Index to my Cluster Master How do I tell my forwarders to send data to the new index

ajromero
Path Finder

I added a third Index to my Cluster Master How do I tell my forwarders to send data to the new index or how my forwarders know about the new index

thank you

Labels (1)
Tags (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

there are two way to do it

  1. manually in outputs.conf 
  2. using indexer discovery with CM

and of course combination of those.

In most cases indexer discovery is the easiest way to manage this especially if you add and remove indexers or those ip/names change regularly. Here is instructions how to configure it https://docs.splunk.com/Documentation/Splunk/8.0.6/Indexer/indexerdiscovery 

If you are using manual method then just add the new one to same stanza in outputs.conf than old ones are. Based on your environment this can do with DS, other automation tool or manually.

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

there are two way to do it

  1. manually in outputs.conf 
  2. using indexer discovery with CM

and of course combination of those.

In most cases indexer discovery is the easiest way to manage this especially if you add and remove indexers or those ip/names change regularly. Here is instructions how to configure it https://docs.splunk.com/Documentation/Splunk/8.0.6/Indexer/indexerdiscovery 

If you are using manual method then just add the new one to same stanza in outputs.conf than old ones are. Based on your environment this can do with DS, other automation tool or manually.

r. Ismo

Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...

New Splunk Innovations Enhance Performance and Accelerate Troubleshooting

Splunk is excited to announce new releases that empower ITOps and engineering teams to stay ahead in ever ...