Deployment Architecture

Search head indexes.conf

TheBravoSierra
Path Finder

Question regarding the indexes.conf on my search heads. Each index contains the paths to the home/cold/thawed directories, but they also have a frozenTimePeriodInSecs value and MaxDataSize. My question is are these two values, FTPIS and MDS, able to removed from the search heads? I thought that the indexers house the values for indexes.conf size requirements and search heads only hold the paths to retrieve the data. Please help me understand.

Thanks

Labels (1)
0 Karma

somesoni2
Revered Legend

The indexes.conf exists on SH so that index names appear on dropdowns (e.g. index name appears when you setup summary index OR in the "Add Data" wizard). Other than that, SH's indexes.conf are not used, you can safely remove/update that file/entry.

Tags (1)

gcusello
SplunkTrust
SplunkTrust

Hi @TheBravoSierra,

in a distributed environment, only the indexes.conf on Indexers are relevant, the ones on Search Heads aren't relevant so you could also delete them (but not relevant) if you configure the forward of all logs to the Indexers.

In other words, you can leave the indexes.conf files on the SHs because aren't relevant.

Anyway, remember to forward all logs to Indexers in each Splunk server (except obviously Indexers!).

Ciao.

Giuseppe

 

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...