All Apps and Add-ons

DB Connect 2 and Search Head Clustering: Should resource pool members be part of the SHC, or separate nodes outside of the SHC?

a212830
Champion

Hi,

I am working on upgrading to Splunk 6.2 and DB Connect 2. In my lab, I have SHC setup, and DB Connect2. Looking at the doc, it looks like db connect on the captain sends request to resource pool members to do the work. Should the resource pool members be part of the SHC, or should they be separate nodes, outside of the SHC.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

separate nodes, they should not be SHC members.

0 Karma

a212830
Champion

Thanks. So, which layer then? Are they independent, and not managed by any of the mgmt tools? (Deployer, CM, Deployment Server)...

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

that's correct -- I assume that if you need pools in addition to SHC, it's because you're pumping data at a significant rate. Forwarders are the ideal home for that.

0 Karma

bandit
Motivator

Wouldn't it be better to have this hosted on the SHC for redundancy of the database feeds? If I lose the forwarder forwarder, don't I lose all db feeds?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

That would be better in theory, but in practice it will not work. On an SHC, only the captain will run DBX jobs.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

Ready to make your IT operations smarter and more efficient? Discover how to automate Splunk alerts with Red ...