Monitoring Splunk

How to I add an indexer to the MC?

Ultra Champion

We added recently indexers and all of them show up as being members of the indexer cluster. How do I add them to the MC?

Tags (2)
0 Karma
1 Solution

Motivator

@ddrillic

Login into the instance where you have setup MC.

Settings -> Management Console -> settings -> General Setup

Under that select mode as distributed. Then Confiugre indexers.

For more details check below link,
https://docs.splunk.com/Documentation/Splunk/6.6.3/DMC/Configureindistributedmode

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

As far as I know you don’t need to add indexers in MC when you are running indexer cluster.

When you point MC to Cluster Master MC will automatically populate list of indexers in MC setup page.

EDIT: Refer point 5 on this link https://docs.splunk.com/Documentation/Splunk/6.6.3/DMC/Addinstancesassearchpeers

Thanks,
Harshil

0 Karma

Ultra Champion

That's what I thought but we did end up in the past year or so adding them one by one...

-- When you point MC to Cluster Master MC....
How do I do that?

0 Karma

SplunkTrust
SplunkTrust

If you want to reconfigure MC then (Before you perform below steps you might need to setup label on IDX cluster)

1.) Remove all indexers which you added manually.

2.) Point MC to CM, (same process when you point stand-alone SH to CM.)

3.) Restart Splunk on MC

4.) Goto MC setup page, here you will see all Indexers populated automatically.

I think I am not missing any point 😛

Thanks,
Harshil

Ultra Champion

Very interesting - let me try it...

0 Karma

Motivator

@ddrillic

Login into the instance where you have setup MC.

Settings -> Management Console -> settings -> General Setup

Under that select mode as distributed. Then Confiugre indexers.

For more details check below link,
https://docs.splunk.com/Documentation/Splunk/6.6.3/DMC/Configureindistributedmode

View solution in original post

0 Karma

Ultra Champion

Right.

-- Settings -> Management Console -> settings -> General Setup
Under that select mode as distributed. Then Confiugre indexers.

I don't see an add button here...

0 Karma

Motivator

execute below steps first and MC to setup labels,

  1. Log into the instance on which you want to configure the Monitoring Console.

  2. In Splunk Web, select Settings > Distributed search > Search peers.

  3. Click New.

  4. Fill in the requested fields and click Save.

  5. Repeat steps 3 and 4 for all instances

Ultra Champion

Perfect. But on step #4, I get this error -

Encountered the following error while trying to save: Status 401 while sending public key to search peer https://<new host>:8089: Unauthorized
0 Karma