Splunk Search

Configure Search Head Cluster Peers to search a single indexer vs. an indexer cluster 6.2.5?

lisaac
Path Finder

I have setup a 6.2.5 SH cluster. The SH cluster consists of 3 SHs and an additional host functioning as a SH deployer. I have successfully configured the SH cluster to communicate with an index cluster. What is the best way to add a single non-clustered indexer to a SH cluster? It looks like I would need to use the CLI and run the command splunk add search-server on each of the SH cluster members. Any thoughts from anyone?

Tags (3)
0 Karma

lguinn2
Legend

Yes, that is how I would do it!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...