Splunk Enterprise

What are the steps to adding an additional peer node/Indexer to a stand alone instance?

nwilliams68
New Member

We currently have our Splunk Enterprise instance all running on a stand-alone vm but are looking to add an additional vm for some sort of replication sort of a hot cold standby option or whatever the best practice may be.  Has anyone had experience doing this and what were your steps? 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk doesn't support standby systems (Splunk 9 introduced a standby Cluster Manager, but doesn't help here).

The Best Practice for replicating data is to use an Indexer Cluster.  An indexer cluster has two more indexers which automatically copy index buckets among themselves.  You'll also need an instance to serve as the Cluster Manager to oversee the indexer cluster and a License Manager.

Going from a standalone instance to a cluster is not trivial - at least if you want to retain your data.  Single-instance buckets have to be converted into clustered buckets (preferably multi-site to allow for future growth).  A Professional Services engagement is recommended.

---
If this reply helps you, Karma would be appreciated.
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

as @richgalloway said the easiest way to do it, is contacting to Splunk PS. If you want to try it by yourself then here is instructions how to convert single peer to indexer cluster https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Migratenon-clusteredindexerstoaclustered.... There is also instruction how to go multisite cluster. You can do multisite cluster also with one site if you don't need it now but maybe later.

Before you start to migrate current one, you should consider is it better to just create a new indexer cluster from scratch and then add both old peer and new cluster as search peers to your SH? Especially if your current search peer has short data retention time this could be a reasonable option.

r. Ismo 

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...