Hello,
I'm looking to set up our search head to send summary index data it generates back to our indexers in a distributed environment.
I found the following question, and I understand the t...
I have a single indexer and single search head with the indexer attached as a search peer and I created one index called "winevent" on the indexer.
I don't understand why the search head cannot s...
...alue combinations and 10's of millions of dups, across a few dozen indexers. The results distribution is likely to be neither sparse nor dense, but long-tail - a few combinations will predominate, w...
Say I have two indexers in two different datacenters, and I want to distributesearches across the WAN/VPN/Internet between them. What kind of bandwidth is necessary for optimal search performance? F...
Hi,
In a distributed mode with 1 search head and 4 indexers, when making a search through the search head, 2 of the for 4 indexers are not showing indexed data except internal logs of other S...
The plan is to scale up a current distributed search framework — from one search head (SH) + one indexer to one SH + two indexers.
We are not planning to use an indexer cluster, so each indexer w...
...ommunicate with it till it indexes have been validates and deemed searchable. Anyone have recommendation on making the indexer upgrade as seamless to the end user as possible? Things t...
Hi all,
My old, primary Splunk indexer/search head is being retired (v4.1.4). In its place is 4 new indexing servers that are carrying the indexing load for me (all running v4.1.5). Each of t...
It looks like indexes on both nodes are updated with the same entries. Does distributed indexing load andindex the same data from a source to both indexers?
UPDATE
It turns out that I've c...
I am testing our new indexer cluster using our existing search head. I added the indexer cluster servers to "dist_search" and created an indexer group so I can search just the cluster. However, a...