I have integrated Search Head cluster with Indexer Cluster. I have the following two requirements now:
1. I want to send data into Search peers from forwarders and search that data from Search Members.
For this i have added a receiving port on the search peers and also ran the command "./splunk add forward-server indexer1:9997 -method autobalance" for all the peers. Still i do not see the data coming in. I am not sure where to validate the data is really coming into the system.
2. To have a dedicated deployment server by running command "./splunk set deploy-poll deploymentserver.splunk.mycompany.com:8089"
Clustering in Splunk is a whole different beast from standalone.
What I would do is go in baby steps and then horizontally expand
1. Install just a standalone splunk
2. Install deployment Server alongside this standalone splunk
3. Now make existing standalone splunk into a Search Head and add a new Indexer
4. and so on...
Also how I've done is to write apps for every thing. (eg. myapp_enable_sh_only : So the systems which receive this app, will be a search head only. Once you design it properly, Splunk works amazingly perfect)
Hello
A Search Head Cluster needs at least 3 Search Heads. In addtition to this, you need to enable receiving (9997) in the indexers, and configure the outputs accordingly in the rest of instances
regards