Splunk® Enterprise

Managing Indexers and Clusters of Indexers

Splunk Enterprise version 9.0 will no longer be supported as of June 14, 2024. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.

Indexer cluster configuration overview

To configure the indexer cluster, you configure the individual nodes. You perform two types of configuration:

  • Configuration of the behavior of the cluster itself.
  • Configuration of the cluster's indexing and search behavior.

The current chapter provides an overview of the ways to configure cluster behavior specifically.

Configuration of each node type

The settings for each node type handle different aspects of the cluster:

  • Manager node. Configuration of overall cluster behavior.
  • Peer node. Configuration of individual peer node and cluster indexing behavior.
  • Search head. Configuration of individual search head and search behavior in an indexer cluster.

See the chapters on specific node types for information on configuring each node type. The chapter "Configure the peers," for example, includes some topics on configuring the peer cluster node settings and other topics that describe how to configure the indexes that a peer uses.

Methods for configuring cluster behavior

Initial configuration of each node occurs during deployment. If you need to change the configuration of a cluster node post-deployment, you have these choices:

Last modified on 22 September, 2020
Connect forwarders directly to peer nodes   Configure the indexer cluster with the dashboards

This documentation applies to the following versions of Splunk® Enterprise: 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.1.12, 8.1.13, 8.1.14, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.1.7, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.3.0, 9.3.1, 9.3.2


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters