Splunk Search

Help with distributed search and multi-site index clustering

Champion

Hi,

I've setup a dev env with 3 sites. I also have a SHC configured, and need to setup distributed search, so the SH read from the IDX.

Looking at this page - http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/SHCandindexercluster - I see the command, but I'm not quite certain on the "site0" part. My sites are site1, site2, site3. The CM is in site1.

So my question is what value should I pass for a site in the cluster-config command.

0 Karma

Splunk Employee
Splunk Employee

The site0 configuration has to do with site affinity in the cluster. When you dont want to bind a SH specifically to a site, it should be site0.

splunk edit cluster-config -mode searchhead -site site0 

This enables it to search across the clusters it is a member of. Note that if this is part of multiple clusters, you'll need to apply that configuration to each cluster its part of.

Conversely, if you wanted to have a SH member, only search specific sites in a cluster, you could adjust that to match siteN.

0 Karma

Champion

And if I'm not using site affinity?

0 Karma

Ultra Champion

@esix is referring to setting up with no site affinity (site0). See this section: http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/DeploymultisiteSHC#Integrate_a_search_...

So in your scenario, you'd leave the CM in site1 and set the search heads all to site0

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!