<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What are some of the best practices of setting up new Splunk servers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341541#M62926</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We recently created 5 new Splunk servers with Windows Server 2016 installed, our current deployment is, 2 indexers, 2 search heads, with a deployment server, is this still the ideal setup? I am new to Splunk so just want to make sure we are doing best practice.&lt;/P&gt;

&lt;P&gt;Our current setup we have Enterprise Security and Core Splunk both on the search heads.&lt;/P&gt;

&lt;P&gt;They all 24 GB of RAM and 6cpu and 6 sockets.&lt;/P&gt;

&lt;P&gt;Eventually, I would like to migrate the old data to the new servers and would like to know is that something that should be done?&lt;/P&gt;</description>
    <pubDate>Wed, 18 Apr 2018 20:15:32 GMT</pubDate>
    <dc:creator>cecampbell</dc:creator>
    <dc:date>2018-04-18T20:15:32Z</dc:date>
    <item>
      <title>What are some of the best practices of setting up new Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341541#M62926</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We recently created 5 new Splunk servers with Windows Server 2016 installed, our current deployment is, 2 indexers, 2 search heads, with a deployment server, is this still the ideal setup? I am new to Splunk so just want to make sure we are doing best practice.&lt;/P&gt;

&lt;P&gt;Our current setup we have Enterprise Security and Core Splunk both on the search heads.&lt;/P&gt;

&lt;P&gt;They all 24 GB of RAM and 6cpu and 6 sockets.&lt;/P&gt;

&lt;P&gt;Eventually, I would like to migrate the old data to the new servers and would like to know is that something that should be done?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 20:15:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341541#M62926</guid>
      <dc:creator>cecampbell</dc:creator>
      <dc:date>2018-04-18T20:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: What are some of the best practices of setting up new Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341542#M62927</link>
      <description>&lt;P&gt;First off, the &lt;STRONG&gt;minimum&lt;/STRONG&gt; requirements for an Enterprise Security search head are 16 physical cores and 32gb of RAM. You should probably start with the following documentation: &lt;A href="http://docs.splunk.com/Documentation/ES/5.0.0/Install/DeploymentPlanning"&gt;http://docs.splunk.com/Documentation/ES/5.0.0/Install/DeploymentPlanning&lt;/A&gt; and &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.3/Capacity/ComponentsofaSplunkEnterprisedeployment"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.3/Capacity/ComponentsofaSplunkEnterprisedeployment&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 20:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341542#M62927</guid>
      <dc:creator>nmiller_splunk</dc:creator>
      <dc:date>2018-04-18T20:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: What are some of the best practices of setting up new Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341543#M62928</link>
      <description>&lt;P&gt;Cecampbell,&lt;BR /&gt;
I'd highly recommend you engage Professional services for this. It sounds like you're new to Splunk and ES is a very complicated product. Based on the information you've provided so far, I'm &lt;STRONG&gt;very&lt;/STRONG&gt; concerned with your deployment and wouldn't recommend going forward with the path you've laid out. Some additional information would be required to make a final judgement, that said my initial reaction is you're on a path for major pain. Some issues I see so far:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Below &lt;STRONG&gt;minimum&lt;/STRONG&gt; specs for CPU (6 socket systems are not a thing, i'm assuming either single socket or dual socket) / Memory&lt;/LI&gt;
&lt;LI&gt;It sounds like ES is installed on both search heads? That's a big issue if so.&lt;/LI&gt;
&lt;LI&gt;Windows (Not a deal breaker, but also going to draw flak from others)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Some additional info that would help:&lt;BR /&gt;
- License size&lt;BR /&gt;
- Current amount of stored data&lt;BR /&gt;
- Storage subsystem&lt;/P&gt;

&lt;P&gt;Again, I'd &lt;STRONG&gt;HIGHLY&lt;/STRONG&gt; recommend engaging Splunk Professional services for this. ES is a complex product, under-sizing it from the get go will be a massive problem. Migrating data is also a complex undertaking with many variables that PS can help with.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 20:57:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341543#M62928</guid>
      <dc:creator>beatus</dc:creator>
      <dc:date>2018-04-18T20:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: What are some of the best practices of setting up new Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341544#M62929</link>
      <description>&lt;P&gt;Thanks for the feedback nmiller, I am unaware they are under sized, our systems team, knew the requirements, but felt as if it was too much resources and advised they will add additional resources once they see that it is needed :(.&lt;/P&gt;

&lt;P&gt;I am following the below document, and have 2 search heads, and 2 indexers, and a deployer.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.3/Deploy/SHCwithindexers"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.3/Deploy/SHCwithindexers&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 12:39:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341544#M62929</guid>
      <dc:creator>cecampbell</dc:creator>
      <dc:date>2018-04-19T12:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: What are some of the best practices of setting up new Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341545#M62930</link>
      <description>&lt;P&gt;Hello Beatus,&lt;/P&gt;

&lt;P&gt;Thanks for the feedback, I will push our team to give more resources.&lt;/P&gt;

&lt;P&gt;The ES is only on the 1 search head.&lt;/P&gt;

&lt;P&gt;We initially used PS, and this is the architecture they recommended, but now we are rebuilding the servers.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.3/Deploy/SHCwithindexers"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.3/Deploy/SHCwithindexers&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 12:42:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341545#M62930</guid>
      <dc:creator>cecampbell</dc:creator>
      <dc:date>2018-04-19T12:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: What are some of the best practices of setting up new Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341546#M62931</link>
      <description>&lt;P&gt;Your systems do not meet the minimum specifications for core Splunk, either. You need to have a serious chat with your systems team, as this will be a very poor experience. Splunk on virtual environments must have reserved resources, and with the negative performance impact of the Meltdown/Spectre patches, having more than minimum resources to run Splunk is generally necessary unless you have a very lightly used environment.&lt;/P&gt;

&lt;P&gt;Next, you cannot have a SHC with only two members. This is 100% not supported.&lt;/P&gt;

&lt;P&gt;Third, if you are not familiar with Enterprise Security &lt;STRONG&gt;or&lt;/STRONG&gt; Search Head Clustering, you will have an extremely steep learning curve implementing both.&lt;/P&gt;

&lt;P&gt;I highly recommend that you step back, read all documentation regarding Enterprise Security and capacity planning, and then reassess your architecture and expertise level before continuing with your current plans.&lt;/P&gt;

&lt;P&gt;The majority of our customers do not implement Enterprise Security without a professional services engagement. &lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 16:40:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341546#M62931</guid>
      <dc:creator>nmiller_splunk</dc:creator>
      <dc:date>2018-04-19T16:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: What are some of the best practices of setting up new Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341547#M62932</link>
      <description>&lt;P&gt;I'll point out again that you cannot have a 2 member SHC. It's not supported. Secondly, you cannot run ES on a single member of a SHC. All apps must be homogenous across a SHC.&lt;/P&gt;

&lt;P&gt;If the intent is to have two &lt;STRONG&gt;separate&lt;/STRONG&gt; search heads, one for ES and one for non-ES, then that is workable, depending on ingest and users' adhoc search load, in a 2 SH/2 IDX environment.  ES consumes large amounts of search head and indexer resources regardless of the ingest level due to DMAs. You will not be able to get by on minimum system resources and have a positive experience.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 16:51:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-some-of-the-best-practices-of-setting-up-new-Splunk/m-p/341547#M62932</guid>
      <dc:creator>nmiller_splunk</dc:creator>
      <dc:date>2018-04-19T16:51:52Z</dc:date>
    </item>
  </channel>
</rss>

