Getting Data In

I added a third Index to my Cluster Master How do I tell my forwarders to send data to the new index

ajromero
Path Finder

I added a third Index to my Cluster Master How do I tell my forwarders to send data to the new index or how my forwarders know about the new index

thank you

Labels (1)
Tags (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

there are two way to do it

  1. manually in outputs.conf 
  2. using indexer discovery with CM

and of course combination of those.

In most cases indexer discovery is the easiest way to manage this especially if you add and remove indexers or those ip/names change regularly. Here is instructions how to configure it https://docs.splunk.com/Documentation/Splunk/8.0.6/Indexer/indexerdiscovery 

If you are using manual method then just add the new one to same stanza in outputs.conf than old ones are. Based on your environment this can do with DS, other automation tool or manually.

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

there are two way to do it

  1. manually in outputs.conf 
  2. using indexer discovery with CM

and of course combination of those.

In most cases indexer discovery is the easiest way to manage this especially if you add and remove indexers or those ip/names change regularly. Here is instructions how to configure it https://docs.splunk.com/Documentation/Splunk/8.0.6/Indexer/indexerdiscovery 

If you are using manual method then just add the new one to same stanza in outputs.conf than old ones are. Based on your environment this can do with DS, other automation tool or manually.

r. Ismo

Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...