Hi folks,
Just a hopefully quick and basic question, I read the following two docs but I am still not quite clear on how and where I should add the SHs and standalone SH instance:
https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console/add-splunk-enterprise-instances-to-the-monitoring-console
https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console/configure-the-monitoring-console-in-distributed-mode
Specifically, we have a Cluster Manager that has a configured MC, with the indexer cluster, fine but there is also a MC on our DS with the same indexers added. So, where would I add the SHs and HFs? I do not want to break the existing configuration but also want to understand this better.
Hi @JohnEGones
Why do you have the MC configured on two different instances? You should really consolidate into a single MC and then take it from there. Check out https://help.splunk.com/en/splunk-enterprise/administer/monitor/10.4/configure-the-monitoring-consol... for recommended MC setup locations.
Once consolidated you can add the SH/HF.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing.