Share a Tip

Question related to clustring

jatin3101
New Member

I was just going thorugh the guide to integrate  the searchhead cluster and indexer cluster . So the last step is to run a command on each of the search head separately ( for integration with manger node ) 

 

so my question is that if in production we had 50-100 search heads then if we strated doing on each search head it will take so much time and efforr isnt their any other way

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi There Dear Splunkers, 

if you are thinking to check the Splunk docs for this task, here it is:

https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/9.4/deploy-search-head-cl...

 

if my post helped you in anyway, a karma would be helpful, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

eyad
New Member

yes

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @jatin3101 

Can you confirm the specific command you are running? If the SH is already part of a cluster then its likely you can push out the relevant configuration via the SH Deployer

For example:

# server.conf
[clustering]
manager_uri = https://yourCM:8089
pass4SymmKey = topSecretPassword

This should connect the SHC members to your IDXC.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

PrewinThomas
Motivator

@jatin3101 

50-100 search heads seems pretty large deployment.

-You can automate this using SH Deployer for SH Cluster members,
Configure server.conf from the deployer and push to all shc members.

-Or use Ansible, Puppet, Chef, or even a shell script with SSH to run the command across all SHs in parallel.


Regards,
Prewin
🌟If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...