Alerting

Build a clustered environment in Prod

man03359
Communicator

Hi!

I have recently moved from out of a Splunk developer role to an admin role. I have to build a cluster environment out of scratch in the on-prem.

I have the basic understanding of a clustered environment but haven't setup yet.

Could you please guide me how can I start. Like what type of knowledge/ information gathering need to do with the client or customer before head. Also if there is any procedure/ order of components to follow.

It will be really helpful for me.

 

Thanks in advance :slightly_smiling_face:

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @man03359,

the design of a clustered Splunk architecture is a job for a Splunk Architect, if you haven't this knowledge or certification, I hint to be supported by a certified one.

Anyway, the phases of your job are the following:

  • requisites analysis (users, data volume, apps to use, scheduled searches, perimeter, types of data sources, etc...),
  • design of the architecture,
  • implementation.

for the last item, you can see at https://docs.splunk.com/Documentation/Splunk/9.2.1/Indexer/Aboutclusters and https://docs.splunk.com/Documentation/Splunk/9.2.1/DistSearch/AboutSHC

For the other two items, a Certified Splunk Architect is mandatory to well design the infrastructure and the architecture.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...