Monitoring Splunk

How to I add an indexer to the MC?

ddrillic
Ultra Champion

We added recently indexers and all of them show up as being members of the indexer cluster. How do I add them to the MC?

Tags (2)
0 Karma
1 Solution

sbbadri
Motivator

@ddrillic

Login into the instance where you have setup MC.

Settings -> Management Console -> settings -> General Setup

Under that select mode as distributed. Then Confiugre indexers.

For more details check below link,
https://docs.splunk.com/Documentation/Splunk/6.6.3/DMC/Configureindistributedmode

View solution in original post

0 Karma

harsmarvania57
SplunkTrust
SplunkTrust

As far as I know you don’t need to add indexers in MC when you are running indexer cluster.

When you point MC to Cluster Master MC will automatically populate list of indexers in MC setup page.

EDIT: Refer point 5 on this link https://docs.splunk.com/Documentation/Splunk/6.6.3/DMC/Addinstancesassearchpeers

Thanks,
Harshil

0 Karma

ddrillic
Ultra Champion

That's what I thought but we did end up in the past year or so adding them one by one...

-- When you point MC to Cluster Master MC....
How do I do that?

0 Karma

harsmarvania57
SplunkTrust
SplunkTrust

If you want to reconfigure MC then (Before you perform below steps you might need to setup label on IDX cluster)

1.) Remove all indexers which you added manually.

2.) Point MC to CM, (same process when you point stand-alone SH to CM.)

3.) Restart Splunk on MC

4.) Goto MC setup page, here you will see all Indexers populated automatically.

I think I am not missing any point 😛

Thanks,
Harshil

ddrillic
Ultra Champion

Very interesting - let me try it...

0 Karma

sbbadri
Motivator

@ddrillic

Login into the instance where you have setup MC.

Settings -> Management Console -> settings -> General Setup

Under that select mode as distributed. Then Confiugre indexers.

For more details check below link,
https://docs.splunk.com/Documentation/Splunk/6.6.3/DMC/Configureindistributedmode

0 Karma

ddrillic
Ultra Champion

Right.

-- Settings -> Management Console -> settings -> General Setup
Under that select mode as distributed. Then Confiugre indexers.

I don't see an add button here...

0 Karma

sbbadri
Motivator

execute below steps first and MC to setup labels,

  1. Log into the instance on which you want to configure the Monitoring Console.

  2. In Splunk Web, select Settings > Distributed search > Search peers.

  3. Click New.

  4. Fill in the requested fields and click Save.

  5. Repeat steps 3 and 4 for all instances

ddrillic
Ultra Champion

Perfect. But on step #4, I get this error -

Encountered the following error while trying to save: Status 401 while sending public key to search peer https://<new host>:8089: Unauthorized
0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...