Monitoring Splunk

How to I add an indexer to the MC?

ddrillic
Ultra Champion

We added recently indexers and all of them show up as being members of the indexer cluster. How do I add them to the MC?

Tags (2)
0 Karma
1 Solution

sbbadri
Motivator

@ddrillic

Login into the instance where you have setup MC.

Settings -> Management Console -> settings -> General Setup

Under that select mode as distributed. Then Confiugre indexers.

For more details check below link,
https://docs.splunk.com/Documentation/Splunk/6.6.3/DMC/Configureindistributedmode

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

As far as I know you don’t need to add indexers in MC when you are running indexer cluster.

When you point MC to Cluster Master MC will automatically populate list of indexers in MC setup page.

EDIT: Refer point 5 on this link https://docs.splunk.com/Documentation/Splunk/6.6.3/DMC/Addinstancesassearchpeers

Thanks,
Harshil

0 Karma

ddrillic
Ultra Champion

That's what I thought but we did end up in the past year or so adding them one by one...

-- When you point MC to Cluster Master MC....
How do I do that?

0 Karma

harsmarvania57
Ultra Champion

If you want to reconfigure MC then (Before you perform below steps you might need to setup label on IDX cluster)

1.) Remove all indexers which you added manually.

2.) Point MC to CM, (same process when you point stand-alone SH to CM.)

3.) Restart Splunk on MC

4.) Goto MC setup page, here you will see all Indexers populated automatically.

I think I am not missing any point 😛

Thanks,
Harshil

ddrillic
Ultra Champion

Very interesting - let me try it...

0 Karma

sbbadri
Motivator

@ddrillic

Login into the instance where you have setup MC.

Settings -> Management Console -> settings -> General Setup

Under that select mode as distributed. Then Confiugre indexers.

For more details check below link,
https://docs.splunk.com/Documentation/Splunk/6.6.3/DMC/Configureindistributedmode

0 Karma

ddrillic
Ultra Champion

Right.

-- Settings -> Management Console -> settings -> General Setup
Under that select mode as distributed. Then Confiugre indexers.

I don't see an add button here...

0 Karma

sbbadri
Motivator

execute below steps first and MC to setup labels,

  1. Log into the instance on which you want to configure the Monitoring Console.

  2. In Splunk Web, select Settings > Distributed search > Search peers.

  3. Click New.

  4. Fill in the requested fields and click Save.

  5. Repeat steps 3 and 4 for all instances

ddrillic
Ultra Champion

Perfect. But on step #4, I get this error -

Encountered the following error while trying to save: Status 401 while sending public key to search peer https://<new host>:8089: Unauthorized
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...