Getting Data In

One search head to search across two separate indexer clusters?

varunmalhotra1
Explorer

I am running two setups of Splunk, one is in Datacenter and another is in AWS.

DC : 2 Node search heads, 3 nodes : indexers, 1 deployment server & license manager
AWS : 2 Node search heads, 3 nodes : indexers, 1 deployment server & license manager

I am trying to add AWS indexer cluster to DC search head. If this is possible we will stop the AWS hosted SHs because we want to keep only one SH cluster which should be able to search across two distinct indexer clusters.
Please note that there is no replication or any connection between the AWS hosted and DC hosted indexer cluster. We don't want to setup multisite indexer clustering.

Can this be done ?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You can add any number of search peers to a search head (non-clustered indexers), or add search heads to any number of cluster masters (clustered indexers).
Then a search will run over all indexers, giving you unified results.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...