Getting Data In

Is it a valid configuration to have indexers on different IP subnets/vlans for a single site in a multisite cluster?

kmarciniak
Path Finder

We have nine sites in a multi-site cluster with indexers at each site ranging from three to 15 servers. Each site's indexers are all on the same vlan and ip subnet for for their region. I have a need to expand one of the sites with more indexers but the vlan has run out of IP addresses. Is it possible to just create a new vlan to use a different IP subnet range and add these new indexers to the previously configured site? For example site2's indexers are in vlan 2 on ip subnet range 10.1.1.0/24. Can I add 6 new indexers to site2 with those new servers in vlan 3 on ip subnet range 11.1.1.0/24?

I looked over the documentation and didn't see a requirement indexers in a site for a multi-site cluster need to all be on the same vlan/ip subnet range but wanted to check if this is a legit configuration from real users in the community. Any pro's and con's? We currently have two independent search heads but are going to a search head cluster later this year.

thank you

0 Karma

nickhills
Ultra Champion

You don't have to have indexers on the same vlan, or subnet. Its totally fine to have them on different subnets.

The only requirement is that they can communicate on the various management, replication and s2s ports

If my comment helps, please give it a thumbs up!
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...