Splunk Enterprise

remote instances are not showing up under monitoring console

Somesh
Explorer

I have setup Cluster master, indexer cluster & Search head cluster. I have a new environment for monitoring console. When I go to  Settings > Monitoring Console > Settings > General Setup  & switch to Distributed mode servers are not showing up under remote instances. Can someone help me on it.

0 Karma

Somesh
Explorer

Nope. Can you provide me the guidelines to add it.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Settings -> Distributed Environment -> Distributed Search -> Search Peers -> Add New

As I said before - for SHC you only need to add the CM, the indexers should populate automatically. The rest of the components you need to add one by one.

Then in the distributed monitoring console you'll have to set up roles for each of those components.

PickleRick
SplunkTrust
SplunkTrust

And did you add your components as search peers to your MC? (for the indexer cluster you only need to add the CM)

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...