Splunk Enterprise

remote instances are not showing up under monitoring console

Somesh
Explorer

I have setup Cluster master, indexer cluster & Search head cluster. I have a new environment for monitoring console. When I go to  Settings > Monitoring Console > Settings > General Setup  & switch to Distributed mode servers are not showing up under remote instances. Can someone help me on it.

0 Karma

Somesh
Explorer

Nope. Can you provide me the guidelines to add it.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Settings -> Distributed Environment -> Distributed Search -> Search Peers -> Add New

As I said before - for SHC you only need to add the CM, the indexers should populate automatically. The rest of the components you need to add one by one.

Then in the distributed monitoring console you'll have to set up roles for each of those components.

gatundu_
Loves-to-Learn

When enabling the MC to run in distributed mode, these are the steps that need to be followed:

  1. Configure the Search Head as a Deployment Server search peer
  2. Configure the Cluster Manager as a Deployment Server search peer
  3. Configure the Deployment Server a cluster search and with search affinity disabled
    ./splunk edit cluster-config -mode searchhead -manager_uri https://<manager-uri-ip>:8089 -secret <secret>
  4. Restart the deployment server

Once the Cluster Manager is added as a Deployment Server search peer, the indexers automatically appear as remote instances on the Monitoring Console

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Here https://help.splunk.com/en/splunk-enterprise/administer/monitor/9.4/configure-the-monitoring-console... is instructions what you need to do.

Remember that you cannot put MC in any instance you want, instead of that you must select correct one. Then as earlier said add all needed nodes as search peers except clusters where you should add only cm.

As @PickleRick said, DS is just one node. Actually don’t configure MC as an additional role for DS! In almost any environment you should have dedicated DS without any other roles!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

No. DS has nothing to do with MC.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

And did you add your components as search peers to your MC? (for the indexer cluster you only need to add the CM)

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...