Hi folks,
Just a hopefully quick and basic question, I read the following two docs but I am still not quite clear on how and where I should add the SHs and standalone SH instance:
https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console/add-splunk-enterprise-instances-to-the-monitoring-console
https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console/configure-the-monitoring-console-in-distributed-mode
Specifically, we have a Cluster Manager that has a configured MC, with the indexer cluster, fine but there is also a MC on our DS with the same indexers added. So, where would I add the SHs and HFs? I do not want to break the existing configuration but also want to understand this better.
Hi @JohnEGones ,
to properly configure the MC, you must connect it to the CM, in this way you have the CM and all the IDXs.
Then you have to connect one by one all the SHs and (if present) the SHC-Deployer, at least the DS.
Beware to a point of attention: it isn't a best practice to put the MC on the DS, particurarly if it has to manage more than 50 clients, it's better to put it on a dedicated server, or on the SHC-Deployer, or, if you have not very large data volumes on the CM: I usually put it on the SHC-Deployer.
About Heavy Forwarders, they are usually not directly monitored by the MC: I usually create some custom dashboards to have all the information that I need and I'm not sure that connecting them to the MC you have the requested inormation.
For more information to connect the MC to the other components see at https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console...
Ciao.
Giuseppe
Hi @JohnEGones ,
to properly configure the MC, you must connect it to the CM, in this way you have the CM and all the IDXs.
Then you have to connect one by one all the SHs and (if present) the SHC-Deployer, at least the DS.
Beware to a point of attention: it isn't a best practice to put the MC on the DS, particurarly if it has to manage more than 50 clients, it's better to put it on a dedicated server, or on the SHC-Deployer, or, if you have not very large data volumes on the CM: I usually put it on the SHC-Deployer.
About Heavy Forwarders, they are usually not directly monitored by the MC: I usually create some custom dashboards to have all the information that I need and I'm not sure that connecting them to the MC you have the requested inormation.
For more information to connect the MC to the other components see at https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console...
Ciao.
Giuseppe
My recommendation is add all HFs, HECs etc as indexers into mc. Then create need subgroups to divide those to reasonable logical sets. Now you can use those groups when you’re selecting target servers in different dashboards. In this way your life is much easier than trying to use on SPL or even separate dashboards.
Hi @JohnEGones
Why do you have the MC configured on two different instances? You should really consolidate into a single MC and then take it from there. Check out https://help.splunk.com/en/splunk-enterprise/administer/monitor/10.4/configure-the-monitoring-consol... for recommended MC setup locations.
Once consolidated you can add the SH/HF.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing.