Splunk Search

Help with distributed search and multi-site index clustering

a212830
Champion

Hi,

I've setup a dev env with 3 sites. I also have a SHC configured, and need to setup distributed search, so the SH read from the IDX.

Looking at this page - http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/SHCandindexercluster - I see the command, but I'm not quite certain on the "site0" part. My sites are site1, site2, site3. The CM is in site1.

So my question is what value should I pass for a site in the cluster-config command.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

The site0 configuration has to do with site affinity in the cluster. When you dont want to bind a SH specifically to a site, it should be site0.

splunk edit cluster-config -mode searchhead -site site0 

This enables it to search across the clusters it is a member of. Note that if this is part of multiple clusters, you'll need to apply that configuration to each cluster its part of.

Conversely, if you wanted to have a SH member, only search specific sites in a cluster, you could adjust that to match siteN.

0 Karma

a212830
Champion

And if I'm not using site affinity?

0 Karma

sloshburch
Splunk Employee
Splunk Employee

@esix is referring to setting up with no site affinity (site0). See this section: http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/DeploymultisiteSHC#Integrate_a_search_...

So in your scenario, you'd leave the CM in site1 and set the search heads all to site0

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...