Splunk Search

Standalone Indexer

rmsit
Communicator

Hi, all.

I am looking to add an indexer to my existing environment that consists of 1 dedicated indexer and 1 dedicated search head. I do not wish to enable clustering as I simply want to introduce load balancing to indexer function. Are there instructions available on how to add a standalone indexer to an existing deployment? Is the process as simple as:

  1. Install Splunk on new instance, point to existing license master
  2. Copy etc/system/local directory from existing indexer to new indexer - this should create any custom props, transforms, inputs, index configurations on new server
  3. Copy etc/apps from existing indexer to new indexer
  4. Configure ouput.conf files on forwarders to load balance
  5. Add new indexer as search peer on search head

Thank you
James

Tags (1)
0 Karma

tdbank
Explorer

Hi rmsit,

Did you add second indexer?

0 Karma

jcunningham63
Loves-to-Learn Lots

Hi tdbank,

Didn't add standalone indexer. I do plan to setup an index cluster from scratch - this was one of my many lessons learned from planning a Splunk deployment.

0 Karma

tdbank
Explorer

Also I plan create indexer cluster environment from distributed environment (existing: one indexer, one searchhead)

To create indexer cluster environment will we need minimum one master cluster and 3 peer nodes?

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi rmsit,

this list looks good to me and it should really be as simple as this.
Make sure to check server.conf if you copy it to the new server, so it will not have the same host/server name as the existing indexer.
And for step 4: it's outputs.conf you should modify 😉

Hope this helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...