<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: deployment server in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/deployment-server/m-p/49020#M1522</link>
    <description>&lt;P&gt;Ok I think ill move my indexer to another box since I have 3 more indexers to handle the work load. Plus in order to save some time I can build my new indexer before I take down the one I need to take out&lt;/P&gt;</description>
    <pubDate>Mon, 04 Mar 2013 21:33:29 GMT</pubDate>
    <dc:creator>hugocvg</dc:creator>
    <dc:date>2013-03-04T21:33:29Z</dc:date>
    <item>
      <title>deployment server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/deployment-server/m-p/49016#M1518</link>
      <description>&lt;P&gt;My splunk instance grew and now my deployment server is not enough.&lt;BR /&gt;
I have 2 search heads, 4 indexers and 261 forwarders. My deployment server is located in the same server as indexer 1 since the instance at first was not so big. I need to know what should I take out of the server, the deployment server or the indexer and how? &lt;BR /&gt;
THNKS&lt;/P&gt;</description>
      <pubDate>Sat, 02 Mar 2013 01:46:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/deployment-server/m-p/49016#M1518</guid>
      <dc:creator>hugocvg</dc:creator>
      <dc:date>2013-03-02T01:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: deployment server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/deployment-server/m-p/49017#M1519</link>
      <description>&lt;P&gt;if you have a linux box, you could run a new instance of splunk on the same box to be the new deployment-server.&lt;BR /&gt;
Change the ports in web.conf ( keep web 8000 for the indexer, and keep management port 8089 for the deployement-server) to avoid conflict.&lt;/P&gt;

&lt;P&gt;That way the deployment-clients will continue to go to the same port, and you just have to update the search-head to point to the new management port of the search-peer.&lt;/P&gt;

&lt;P&gt;If you are  on windows .... install a new server.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Mar 2013 16:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/deployment-server/m-p/49017#M1519</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-03-02T16:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: deployment server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/deployment-server/m-p/49018#M1520</link>
      <description>&lt;P&gt;If it's easy for you to modify the clients to point to a new address of the DS, then that will probably be easier. But you would have to have a way to change the settings of all 261 clients. If (only if) the location of the DS is &lt;EM&gt;not&lt;/EM&gt; set in $SPLUNK_HOME/etc/system/local, but instead in an app, it's possible to push out a new app to use DS to update the clients, but this is a tricky thing to coordinate even assuming you're in a position to do it at all.&lt;/P&gt;

&lt;P&gt;Otherwise, you could move your indexer. As yannK says, you can do it just by changing the Splunk ports, and then updating the two search heads, which is pretty easy. That still leaves both indexer and DS on the same server, but may be good enough to last you a bit longer though.&lt;/P&gt;

&lt;P&gt;Finally, you can try to move the indexer to a new machine. There's a bit more config, and the data may take a while to move, but again, you would only need to update the two search heads, plus use Deployment server to update the forwarding targets of all the clients.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Mar 2013 21:17:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/deployment-server/m-p/49018#M1520</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2013-03-02T21:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: deployment server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/deployment-server/m-p/49019#M1521</link>
      <description>&lt;P&gt;BTW, this is why we usually recommend using distinct host name aliases for each Splunk service, even if they're all running on the same instance of Splunk.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Mar 2013 21:18:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/deployment-server/m-p/49019#M1521</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2013-03-02T21:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: deployment server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/deployment-server/m-p/49020#M1522</link>
      <description>&lt;P&gt;Ok I think ill move my indexer to another box since I have 3 more indexers to handle the work load. Plus in order to save some time I can build my new indexer before I take down the one I need to take out&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2013 21:33:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/deployment-server/m-p/49020#M1522</guid>
      <dc:creator>hugocvg</dc:creator>
      <dc:date>2013-03-04T21:33:29Z</dc:date>
    </item>
  </channel>
</rss>

