Alerting

Build a clustered environment in Prod

man03359
Communicator

Hi!

I have recently moved from out of a Splunk developer role to an admin role. I have to build a cluster environment out of scratch in the on-prem.

I have the basic understanding of a clustered environment but haven't setup yet.

Could you please guide me how can I start. Like what type of knowledge/ information gathering need to do with the client or customer before head. Also if there is any procedure/ order of components to follow.

It will be really helpful for me.

 

Thanks in advance :slightly_smiling_face:

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @man03359,

the design of a clustered Splunk architecture is a job for a Splunk Architect, if you haven't this knowledge or certification, I hint to be supported by a certified one.

Anyway, the phases of your job are the following:

  • requisites analysis (users, data volume, apps to use, scheduled searches, perimeter, types of data sources, etc...),
  • design of the architecture,
  • implementation.

for the last item, you can see at https://docs.splunk.com/Documentation/Splunk/9.2.1/Indexer/Aboutclusters and https://docs.splunk.com/Documentation/Splunk/9.2.1/DistSearch/AboutSHC

For the other two items, a Certified Splunk Architect is mandatory to well design the infrastructure and the architecture.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...