Alerting

Build a clustered environment in Prod

man03359
Communicator

Hi!

I have recently moved from out of a Splunk developer role to an admin role. I have to build a cluster environment out of scratch in the on-prem.

I have the basic understanding of a clustered environment but haven't setup yet.

Could you please guide me how can I start. Like what type of knowledge/ information gathering need to do with the client or customer before head. Also if there is any procedure/ order of components to follow.

It will be really helpful for me.

 

Thanks in advance :slightly_smiling_face:

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @man03359,

the design of a clustered Splunk architecture is a job for a Splunk Architect, if you haven't this knowledge or certification, I hint to be supported by a certified one.

Anyway, the phases of your job are the following:

  • requisites analysis (users, data volume, apps to use, scheduled searches, perimeter, types of data sources, etc...),
  • design of the architecture,
  • implementation.

for the last item, you can see at https://docs.splunk.com/Documentation/Splunk/9.2.1/Indexer/Aboutclusters and https://docs.splunk.com/Documentation/Splunk/9.2.1/DistSearch/AboutSHC

For the other two items, a Certified Splunk Architect is mandatory to well design the infrastructure and the architecture.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...