<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: in a Splunk Distributed Environment, what is the limit of indexers by a single dedicated search head? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422668#M15069</link>
    <description>&lt;P&gt;Out if curiousity, would the remote indexer you're planning on better suited as a heavy forwarder that just sends traffic back to your main indexers at the other end of the VPN tunnel? Seems like the easiest way to avoid latency issues depending on the distance.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Dec 2018 01:25:54 GMT</pubDate>
    <dc:creator>jmaple_splunk</dc:creator>
    <dc:date>2018-12-06T01:25:54Z</dc:date>
    <item>
      <title>in a Splunk Distributed Environment, what is the limit of indexers by a single dedicated search head?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422665#M15066</link>
      <description>&lt;P&gt;I have Splunk distributed 7.2.1 (1 dedicated Search Head with multilple non clustered indexers) &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;I am wondering if there is a limit of indexers by a single dedicated search head ( &lt;STRONG&gt;how many indexers can a search head support ?&lt;/STRONG&gt; )&lt;/LI&gt;
&lt;LI&gt;i am planning on adding a distant instance of Splunk Enterprise as an &lt;STRONG&gt;indexer over VPN&lt;/STRONG&gt; (based on client request). Is that possible ? &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Note: the dedicated search head is acting as deployment server and license manager as well.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 15:38:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422665#M15066</guid>
      <dc:creator>arlakathena</dc:creator>
      <dc:date>2018-12-04T15:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: in a Splunk Distributed Environment, what is the limit of indexers by a single dedicated search head?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422666#M15067</link>
      <description>&lt;OL&gt;
&lt;LI&gt;I don't think there is a limit in this case, for instance we had a stand-alone search head with 20peers(indexers)&lt;/LI&gt;
&lt;LI&gt;You can add as long as the Search Head is able to communicate with the Indexer over VPN, but you might encounter some network latency. &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;This splunk doc might give you an idea on scaling your infrastructure..&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.1/Capacity/Summaryofperformancerecommendations"&gt;http://docs.splunk.com/Documentation/Splunk/7.2.1/Capacity/Summaryofperformancerecommendations&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 17:40:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422666#M15067</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2018-12-04T17:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: in a Splunk Distributed Environment, what is the limit of indexers by a single dedicated search head?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422667#M15068</link>
      <description>&lt;P&gt;The Search head uses &lt;STRONG&gt;"URL:8089"&lt;/STRONG&gt;&lt;BR /&gt;
As long as it can connect to it should not be any problems. &lt;/P&gt;

&lt;P&gt;But the underlaying infastructure may be using som CPU resources. Is the VPN a software or is it Site2Site vpn. &lt;BR /&gt;
You will most likely encounter some lag, but I think it wil work. &lt;/P&gt;

&lt;P&gt;But it all depends on network and the cpu/memory of the Search head. &lt;BR /&gt;
The indexer you are pulling data from wil not even know if youre on another network. &lt;/P&gt;

&lt;P&gt;But if you can reach the indexer/peer via the VPN tunnell you are all good. &lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 15:16:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422667#M15068</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2018-12-05T15:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: in a Splunk Distributed Environment, what is the limit of indexers by a single dedicated search head?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422668#M15069</link>
      <description>&lt;P&gt;Out if curiousity, would the remote indexer you're planning on better suited as a heavy forwarder that just sends traffic back to your main indexers at the other end of the VPN tunnel? Seems like the easiest way to avoid latency issues depending on the distance.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2018 01:25:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422668#M15069</guid>
      <dc:creator>jmaple_splunk</dc:creator>
      <dc:date>2018-12-06T01:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: in a Splunk Distributed Environment, what is the limit of indexers by a single dedicated search head?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422669#M15070</link>
      <description>&lt;P&gt;When the client chooses that the data stays stored locally at his side we can't judge him! also i would need another indexer at my side to receive parsed event coming from the heavy forwarder as you suggested! &lt;/P&gt;

&lt;P&gt;My point here that i would search data through my dedicated Search Head (no local storage/index) to the indexer(at the client side) via VPN, data will be stored there, his license will be a slave of my license manager&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2018 08:57:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422669#M15070</guid>
      <dc:creator>arlakathena</dc:creator>
      <dc:date>2018-12-06T08:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: in a Splunk Distributed Environment, what is the limit of indexers by a single dedicated search head?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422670#M15071</link>
      <description>&lt;P&gt;The Search Head is deployed with the best practice hardware requirements so i don't think there will be a problem there. &lt;BR /&gt;
The best way i'm planning this is on a Site2Site VPN, i think the network capacity is extensible so logically there is no problem.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2018 09:02:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422670#M15071</guid>
      <dc:creator>arlakathena</dc:creator>
      <dc:date>2018-12-06T09:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: in a Splunk Distributed Environment, what is the limit of indexers by a single dedicated search head?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422671#M15072</link>
      <description>&lt;P&gt;Please let us know how it went, if you are experiencing lag then you could  adjust the timeout on the Search head.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2018 11:13:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422671#M15072</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2018-12-06T11:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: in a Splunk Distributed Environment, what is the limit of indexers by a single dedicated search head?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422672#M15073</link>
      <description>&lt;P&gt;It's working for 2 months now ! &lt;BR /&gt;
no break ups or failures &lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 15:52:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422672#M15073</guid>
      <dc:creator>arlakathena</dc:creator>
      <dc:date>2019-02-26T15:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: in a Splunk Distributed Environment, what is the limit of indexers by a single dedicated search head?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422673#M15074</link>
      <description>&lt;P&gt;Wonderful:)&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 07:49:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/in-a-Splunk-Distributed-Environment-what-is-the-limit-of/m-p/422673#M15074</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-02-27T07:49:42Z</dc:date>
    </item>
  </channel>
</rss>

