Deployment Architecture

Cluster question

dolejh76
Communicator

We have a server in Omaha and a server in Jacksonville.

Currently all items are forwarded to Omaha so when I log into Omaha I can see Omaha and Jacksonville. When I log into Jacksonville I cant see anything.

How do I set it so that in Jacksonville I can see Jacksonville. I don't want to replicate all Omaha indexes to Jacksonville, but I would like to be able to see Jacksonville when logged into Jacksonville.

Thanks
John

Tags (1)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Sounds to me like you are not indexing in Jacksonville, you are just forwarding events.

You either need to index and forward events from Jacksonville, or you need setup distributed search from the Jacksonville instance(s).

Read this : https://docs.splunk.com/Documentation/Splunk/6.5.2/DistSearch/Configuredistributedsearch

What you want to do is add the Omaha indexer as a peer to Jacksonville. Be aware there are some bandwidth and latency issues to be considerate of...

0 Karma

dolejh76
Communicator

Ill take a look - thanks

0 Karma

somesoni2
Revered Legend

Does your search head has both Omaha and Jacksonville indexers added as Search Peer?

0 Karma

dolejh76
Communicator

Logged into Omaha - I see Jax as a Peer, and Omaha as a search head.

0 Karma

somesoni2
Revered Legend

What you do see in Jacksonville? Do you see Omaha as Peer?

0 Karma

dolejh76
Communicator

If I log into Jax - I just see - Clustering: Peer Node and Jax.

0 Karma

mrgibbon
Contributor

Sounds like you need to add Omaha as a search peer on the Jax machine.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...