Splunk Search

Standalone Indexer

rmsit
Communicator

Hi, all.

I am looking to add an indexer to my existing environment that consists of 1 dedicated indexer and 1 dedicated search head. I do not wish to enable clustering as I simply want to introduce load balancing to indexer function. Are there instructions available on how to add a standalone indexer to an existing deployment? Is the process as simple as:

  1. Install Splunk on new instance, point to existing license master
  2. Copy etc/system/local directory from existing indexer to new indexer - this should create any custom props, transforms, inputs, index configurations on new server
  3. Copy etc/apps from existing indexer to new indexer
  4. Configure ouput.conf files on forwarders to load balance
  5. Add new indexer as search peer on search head

Thank you
James

Tags (1)
0 Karma

tdbank
Explorer

Hi rmsit,

Did you add second indexer?

0 Karma

jcunningham63
Loves-to-Learn Lots

Hi tdbank,

Didn't add standalone indexer. I do plan to setup an index cluster from scratch - this was one of my many lessons learned from planning a Splunk deployment.

0 Karma

tdbank
Explorer

Also I plan create indexer cluster environment from distributed environment (existing: one indexer, one searchhead)

To create indexer cluster environment will we need minimum one master cluster and 3 peer nodes?

0 Karma

MuS
Legend

Hi rmsit,

this list looks good to me and it should really be as simple as this.
Make sure to check server.conf if you copy it to the new server, so it will not have the same host/server name as the existing indexer.
And for step 4: it's outputs.conf you should modify 😉

Hope this helps ...

cheers, MuS

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...