Splunk Search

Help with distributed search and multi-site index clustering

a212830
Champion

Hi,

I've setup a dev env with 3 sites. I also have a SHC configured, and need to setup distributed search, so the SH read from the IDX.

Looking at this page - http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/SHCandindexercluster - I see the command, but I'm not quite certain on the "site0" part. My sites are site1, site2, site3. The CM is in site1.

So my question is what value should I pass for a site in the cluster-config command.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

The site0 configuration has to do with site affinity in the cluster. When you dont want to bind a SH specifically to a site, it should be site0.

splunk edit cluster-config -mode searchhead -site site0 

This enables it to search across the clusters it is a member of. Note that if this is part of multiple clusters, you'll need to apply that configuration to each cluster its part of.

Conversely, if you wanted to have a SH member, only search specific sites in a cluster, you could adjust that to match siteN.

0 Karma

a212830
Champion

And if I'm not using site affinity?

0 Karma

sloshburch
Splunk Employee
Splunk Employee

@esix is referring to setting up with no site affinity (site0). See this section: http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/DeploymultisiteSHC#Integrate_a_search_...

So in your scenario, you'd leave the CM in site1 and set the search heads all to site0

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...