Deployment Architecture

There is no "search head clustering" below "settings" in my SH cluster member's web

danielwan
Explorer

I have built an SH cluster and an indexer cluster with Splunk 6.5.4 . I would like to monitor SH cluster via Splunk web.

I followed the following document (I note it's a Splunk 7.0 document)

http://docs.splunk.com/Documentation/Splunk/7.0.1/DistSearch/SHCsettings

But below DISTRIBUTED ENVIRONMENT of settings on my SH captain (a static captain than dynamic captain), there is no "search head clustering" at all, instead, there are 3 menu items, which are Indexer clustering, Forwarder management and Distributed search.

I can list my SH cluster details properly via CLI, e.g. splunk show shcluster-status and splunk list shcluster-members.

Is monitoring SH cluster via Splunk web available in Splunk 6.5? How to enable it?

0 Karma

adonio
Ultra Champion

hello there,

the only GUI indication that you have a SHC is that the settings menu is not full (although you can click on an icon that will enable it)
also, if using a load balancer, your url will be different then the host you are on (help button and then about button)
not sure what do you mean by monitoring the SHC but if you would like to see metrics about replication, long searches and SHC health, use the MC (Splunk monitoring console)

hope it helps

0 Karma

danielwan
Explorer

I have clicked "show all menus", I also walked through my SH captain and SH peer one by one, only saw Distributed search but not Search Head Clustering in the menu.

Yes, I want to monitor SHC metrics. Splunk web would be much easier than CLI.

My SH does not have MC(Splunk monitoring console), only indexer cluster member has MC.

How to enable MC on SH member?

0 Karma

adonio
Ultra Champion

add your SHC Members and Deployer to the MC
link:
http://docs.splunk.com/Documentation/Splunk/7.0.1/DMC/Configureindistributedmode
here is the full description of views and functions out of the box (MC)
http://docs.splunk.com/Documentation/Splunk/7.0.1/DMC/SHCdashboards

hope it helps

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...