Monitoring Splunk

Properly configuring the Monitoring Console

JohnEGones
Communicator

Hi folks,

 

Just a hopefully quick and basic question, I read the following two docs but I am still not quite clear on how and where I should add the SHs and standalone SH instance:

 

https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console/add-splunk-enterprise-instances-to-the-monitoring-console

https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console/configure-the-monitoring-console-in-distributed-mode

 

Specifically, we have a Cluster Manager that has a configured MC, with the indexer cluster, fine but there is also a MC on our DS with the same indexers added. So, where would I add the SHs and HFs? I do not want to break the existing configuration but also want to understand this better.

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @JohnEGones ,

to properly configure the MC, you must connect it to the CM, in this way you have the CM and all the IDXs.

Then you have to connect one by one all the SHs and (if present) the SHC-Deployer, at least the DS.

Beware to a point of attention: it isn't a best practice to put the MC on the DS, particurarly if it has to manage more than 50 clients, it's better to put it on a dedicated server, or on the SHC-Deployer, or, if you have not very large data volumes on the CM: I usually put it on the SHC-Deployer.

About Heavy Forwarders, they are usually not directly monitored by the MC: I usually create some custom dashboards to have all the information that I need and I'm not sure that connecting them to the MC you have the requested inormation.

For more information to connect the MC to the other components see at https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console...

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @JohnEGones ,

to properly configure the MC, you must connect it to the CM, in this way you have the CM and all the IDXs.

Then you have to connect one by one all the SHs and (if present) the SHC-Deployer, at least the DS.

Beware to a point of attention: it isn't a best practice to put the MC on the DS, particurarly if it has to manage more than 50 clients, it's better to put it on a dedicated server, or on the SHC-Deployer, or, if you have not very large data volumes on the CM: I usually put it on the SHC-Deployer.

About Heavy Forwarders, they are usually not directly monitored by the MC: I usually create some custom dashboards to have all the information that I need and I'm not sure that connecting them to the MC you have the requested inormation.

For more information to connect the MC to the other components see at https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.2/configure-the-monitoring-console...

Ciao.

Giuseppe

isoutamo
SplunkTrust
SplunkTrust

My recommendation is add all HFs, HECs etc as indexers into mc. Then create need subgroups to divide those to reasonable logical sets. Now you can use those groups when you’re selecting target servers in different dashboards. In this way your life is much easier than trying to use on SPL or even separate dashboards.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @JohnEGones 

Why do you have the MC configured on two different instances? You should really consolidate into a single MC and then take it from there. Check out https://help.splunk.com/en/splunk-enterprise/administer/monitor/10.4/configure-the-monitoring-consol... for recommended MC setup locations.

Once consolidated you can add the SH/HF.

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...