Hi sir/ma'am
I have a 8 servers with splunk and splunkforwarder
Server 1 - indexer1 ( with Splunk )
Server 2 - indexer2 ( with Splunk )
Server 3 - indexer3 ( with Splunk )
Server 4 - indexer4 ( with Splunk )
server 5 - indexer5 ( with Splunk )
server 6 - Logs Server ( with Splunk forwarder and syslog-ng)
server 7 - search head ( with Splunk )
server 8 - summary indexing ( with Splunk )
And now this is my set-up on
Logs Server are now sending logs with the 5 indexer2
and
the the search head are now configured the listen into the 5 indexers using search peer in splunk and its working..
Now my question is
How i can set-up a summary indexing with my summary indexing server? that can search my created index in summary indexing server into my search head server
i tried my own set-up but i not quiet sure if i am right
this is my set-up
in summary indexing server i create search peer located at distributed search listening to the 5 indexing server and now i can view the logs came from the indexing servers and also i create a new index named sample_summary and also a create a search with summary indexing enable pointed with my new created index and now i check my created index and now it have a data.
so next step is to check into search head and its now searchable i used this kind of search string
( splunk_server="xxx-xxxxx" index=sample_summary )
Thats my current set-up
Let e know if i need to elaborate my question more
thanks and best regards
Cris
Sorry with my little poor English ^_^
... View more