Splunk Search

Standalone Indexer

rmsit
Communicator

Hi, all.

I am looking to add an indexer to my existing environment that consists of 1 dedicated indexer and 1 dedicated search head. I do not wish to enable clustering as I simply want to introduce load balancing to indexer function. Are there instructions available on how to add a standalone indexer to an existing deployment? Is the process as simple as:

  1. Install Splunk on new instance, point to existing license master
  2. Copy etc/system/local directory from existing indexer to new indexer - this should create any custom props, transforms, inputs, index configurations on new server
  3. Copy etc/apps from existing indexer to new indexer
  4. Configure ouput.conf files on forwarders to load balance
  5. Add new indexer as search peer on search head

Thank you
James

Tags (1)
0 Karma

tdbank
Explorer

Hi rmsit,

Did you add second indexer?

0 Karma

jcunningham63
Loves-to-Learn Lots

Hi tdbank,

Didn't add standalone indexer. I do plan to setup an index cluster from scratch - this was one of my many lessons learned from planning a Splunk deployment.

0 Karma

tdbank
Explorer

Also I plan create indexer cluster environment from distributed environment (existing: one indexer, one searchhead)

To create indexer cluster environment will we need minimum one master cluster and 3 peer nodes?

0 Karma

MuS
Legend

Hi rmsit,

this list looks good to me and it should really be as simple as this.
Make sure to check server.conf if you copy it to the new server, so it will not have the same host/server name as the existing indexer.
And for step 4: it's outputs.conf you should modify 😉

Hope this helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...