Splunk® Enterprise

Managing Indexers and Clusters of Indexers

Acrobat logo Download manual as PDF


Splunk Enterprise version 7.2 is no longer supported as of April 30, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Add a peer to the cluster

You can add peer nodes to the indexer cluster at any time. To do so, just enable a Splunk Enterprise instance as a peer node.

Before you enable a peer node, familiarize yourself with the relevant system requirements, detailed in System requirements and other deployment considerations for indexer clusters. Ensure that the Splunk Enterprise instance meets the version compatibility and all other documented requirements.

For single-site clusters, follow one of these procedures:

To enable a peer node for a multisite cluster, see Configure multisite indexer clusters with server.conf.

When the peer starts up, the master node distributes the latest configuration bundle to the peer. This process ensures that the new peer has the same set of configurations, including the set of indexes and other index settings, as the other peer nodes. See Distribution of the bundle when a peer starts up.

After you enable the peer node, you might need to take steps to ensure that the peer is receiving data from forwarders. There are a variety of ways to configure the relationship between forwarders and peer nodes. Depending on how your cluster connects to forwarders, you might need to configure either the new peer node or the forwarders, or both. For details, read the topics in the chapter Get data into the indexer cluster.

As a final step, consider rebalancing the cluster's data, so that existing data gets moved onto the new peer node. This allows the new peer to share the search burden. See Rebalance indexer cluster data.

Last modified on 02 October, 2020
PREVIOUS
Use the monitoring console to view indexer cluster status
  NEXT
Take a peer offline

This documentation applies to the following versions of Splunk® Enterprise: 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters