Hi,
I have 2 Indexer and 1 SearchHead. Where should the data from my summary of the SH or the Indexer?
I checked and in my case they are in HS. Is this correct? I do not think anything in the documentation about this.
Regards,
Erick Eduardo
Well it depends. It's not a matter of what is 'correct' - if you want the summarized data to reside on the search head, that's fine. If you want your indexers to have all data, you need to configure your search head to forward the summary events to your indexers. This is a very common question, here are some previous questions and corresponding answers:
http://answers.splunk.com/answers/5837/summary-indexing-on-a-search-head
http://answers.splunk.com/answers/39314/how-do-you-handle-summary-indexing-in-a-distributed-environm...
http://answers.splunk.com/answers/69365/forwarding-summary-index-from-search-head-to-indexer
If I send my summary to the indexers, improve the performance of search?