Monitoring Splunk

How to configure the Splunk Deployment Monitor app on a multisite cluster in order to see all Indexers in the UI?

aof
New Member

I have one cluster in two geographic sites.
Server1 (SearchHead), server3(Indexer), server5(Indexer) on site1 AND Server2(SearchHead), server4(Indexer), server6(Indexer) on site 2

Cluster Master replication configuration :
[clustering]
access_logging_for_heartbeats = 1
available_sites = site1,site2
max_peer_build_load = 5
mode = master
multisite = true
pass4SymmKey = xxxxxxxxxxxxxxxxx
replication_factor = 2
site_replication_factor = origin:1,site1:1,site2:1,total:2
site_search_factor = origin:1,site1:1,site2:1,total:2

The Search Heads send their logs to all four indexers in LB mode.

The Deployment Monitor app is installed on server 1. On the DM interface I can see only the servers 1, 2 and 3.
If I change #site=site1 by #site=site2 (server.conf  stanza [general]), on the DM interface I can see now only the servers 2, 4 and 6.
Are there some settings to configure in order to see all the servers on the DM interface?

However with the SoS app on the SearchHead (Server1), all components of my architecture are visible.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

You need to join the SH with the Deployment Monitor Console to the remote cluster, as a search peer.

0 Karma

dolivasoh
Contributor

I believe this is a search affinity issue. Try ensuring the deployment monitor instance is configured to use all indexers as distributed search peers.

0 Karma

aof
New Member

Hi,
How do you configure the Deploymment Monitor to use all indexers as distributed search peers ?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...