Splunk Enterprise

What are the steps to adding an additional peer node/Indexer to a stand alone instance?

nwilliams68
New Member

We currently have our Splunk Enterprise instance all running on a stand-alone vm but are looking to add an additional vm for some sort of replication sort of a hot cold standby option or whatever the best practice may be.  Has anyone had experience doing this and what were your steps? 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk doesn't support standby systems (Splunk 9 introduced a standby Cluster Manager, but doesn't help here).

The Best Practice for replicating data is to use an Indexer Cluster.  An indexer cluster has two more indexers which automatically copy index buckets among themselves.  You'll also need an instance to serve as the Cluster Manager to oversee the indexer cluster and a License Manager.

Going from a standalone instance to a cluster is not trivial - at least if you want to retain your data.  Single-instance buckets have to be converted into clustered buckets (preferably multi-site to allow for future growth).  A Professional Services engagement is recommended.

---
If this reply helps you, Karma would be appreciated.
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

as @richgalloway said the easiest way to do it, is contacting to Splunk PS. If you want to try it by yourself then here is instructions how to convert single peer to indexer cluster https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Migratenon-clusteredindexerstoaclustered.... There is also instruction how to go multisite cluster. You can do multisite cluster also with one site if you don't need it now but maybe later.

Before you start to migrate current one, you should consider is it better to just create a new indexer cluster from scratch and then add both old peer and new cluster as search peers to your SH? Especially if your current search peer has short data retention time this could be a reasonable option.

r. Ismo 

0 Karma
Get Updates on the Splunk Community!

Changes to Splunk Instructor-Led Training Completion Criteria

We’re excited to share an update to our instructor-led training program that enhances the learning experience ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

❄️ Welcome the new year with our January lineup of Community Office Hours, Tech Talks, and Webinars! 🎉 ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...