Splunk Enterprise

remote instances are not showing up under monitoring console

Somesh
Explorer

I have setup Cluster master, indexer cluster & Search head cluster. I have a new environment for monitoring console. When I go to  Settings > Monitoring Console > Settings > General Setup  & switch to Distributed mode servers are not showing up under remote instances. Can someone help me on it.

0 Karma

Somesh
Explorer

Nope. Can you provide me the guidelines to add it.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Settings -> Distributed Environment -> Distributed Search -> Search Peers -> Add New

As I said before - for SHC you only need to add the CM, the indexers should populate automatically. The rest of the components you need to add one by one.

Then in the distributed monitoring console you'll have to set up roles for each of those components.

gatundu_
Loves-to-Learn

When enabling the MC to run in distributed mode, these are the steps that need to be followed:

  1. Configure the Search Head as a Deployment Server search peer
  2. Configure the Cluster Manager as a Deployment Server search peer
  3. Configure the Deployment Server a cluster search and with search affinity disabled
    ./splunk edit cluster-config -mode searchhead -manager_uri https://<manager-uri-ip>:8089 -secret <secret>
  4. Restart the deployment server

Once the Cluster Manager is added as a Deployment Server search peer, the indexers automatically appear as remote instances on the Monitoring Console

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Here https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.4/configure-the-monitoring-console... is instructions what you need to do.

Remember that you cannot put MC in any instance you want, instead of that you must select correct one. Then as earlier said add all needed nodes as search peers except clusters where you should add only cm.

As @PickleRick said, DS is just one node. Actually don’t configure MC as an additional role for DS! In almost any environment you should have dedicated DS without any other roles!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

No. DS has nothing to do with MC.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

And did you add your components as search peers to your MC? (for the indexer cluster you only need to add the CM)

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...