@somesoni2,
After reading steps mentioned in links provided by you,
I added stanza 'indexer_discovery' to the bottom part of
server.conf on idx01 (indexer-master) and outputs.conf (universal forwarder).
I did 'splunk restart' on idx01 and uf01.
However, I see consistent ERROR on universal forwarder's log.
No Error on Indexer-master's log (splunkd.log).
Is that ERROR on unvirsal forwarder's a legit error or can be ignored?
INDEXER-MASTER
--------------
# cat server.conf
[general]
serverName = idx01
pass4SymmKey = $1$oNHXGCjyfX/G
site = default
[sslConfig]
sslPassword = $1$952DRG20Ni3G
[lmpool:auto_generated_pool_download-trial]
description = auto_generated_pool_download-trial
quota = MAX
slaves = *
stack_id = download-trial
[lmpool:auto_generated_pool_forwarder]
description = auto_generated_pool_forwarder
quota = MAX
slaves = *
stack_id = forwarder
[lmpool:auto_generated_pool_free]
description = auto_generated_pool_free
quota = MAX
slaves = *
stack_id = free
[clustering]
access_logging_for_heartbeats = 1
cluster_label = qpsplunk
max_peer_build_load = 5
mode = master
pass4SymmKey = $1$ssndEzbb
service_interval = 1
[indexer_discovery]
pass4SymmKey = $1$ssnFEyzldW7G
polling_rate = 10
indexerWeightByDiskCapacity = FALSE
UNIFERSAL FORWARDER
-------------------
# cat outputs.conf
[indexer_discovery:qpsplunkdiscovery]
pass4SymmKey = $1$M05xrAKiR/Vn
master_uri = https://idx01:8089
[tcpout:group1]
autoLBFrequencey = 30
forceTimebasedAutoLB = true
indexerDiscovery = qpsplunkdiscovery
useACK = true
[tcpout]
defaultGroup = group1
UNIVERSAL FORWARDER
-------------------
[root@uf01 0 /opt/splunkforwarder/bin]# less ../var/log/splunk/splunkd.log
10-18-2016 20:16:04.997 +0000 ERROR IndexerDiscoveryHeartbeatThread - failed to parse response payload for group=group1, err=failed to extract FwdTarget from json node={"hostport":"?","ssl":false,"indexing_disk_space":-1}http_response=OK
10-18-2016 20:16:10.006 +0000 ERROR IndexerDiscoveryHeartbeatThread - failed to parse response payload for group=group1, err=failed to extract FwdTarget from json node={"hostport":"?","ssl":false,"indexing_disk_space":-1}http_response=OK
INDEXER
-------
[root@idx01 0 /opt/splunk/bin]# less ../var/log/splunk/splunkd.log
10-18-2016 20:07:58.941 +0000 INFO CMIndexerDiscovery - Request rate limiting = 10 requests per second
10-18-2016 20:07:58.941 +0000 INFO CMIndexerDiscovery - Indexer weight by disk capacity = 0
10-18-2016 20:07:58.941 +0000 INFO CMIndexerDiscovery - Registering new forwarder 5AB0AD22-839F-4340-89EC-7CCC6E3C1F8F (total: 1). Heartbeat assigned for next check: 30 seconds
10-18-2016 20:08:23.655 +0000 WARN DistributedBundleReplicationManager - Asynchronous bundle replication to 3 peer(s) succeeded; however it took too long (longer than 10 seconds): elapsed_ms=19134, tar_elapsed_ms=3751, bundle_file_size=76000KB, replication_id=1476821284, replication_reason="async replication allowed"
... View more