All Apps and Add-ons

Dedicated SH for Machine Learning Team

jonaclough
Path Finder

We have a 7 node SH multisite cluster, behind a VIP/LB. The ML team are coming up against limits for searches - some of which can be set on a user/search basis. However some limits are global (e.g. subsearch) and we cannot change these settings without risking platform instability.

The plan is to create a dedicated search head for the ML team. It would be part of the cluster but not behind the VIP. The ML team would get a separate GUI and REST VIP which would target the new SH.

The extra SH would mean an even number but I think this is OK if we ensure there is always an odd number in each site (5/3 in our case)

Does this sound like a sensible solution? 

 

 

 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, that's sensible.  Keep in mind, however, that a SH that is part of a cluster is not truly "dedicated".  While only the ML may sign in to it, the SHC captain may choose to assign scheduled searches to any SHC member, including the ML node.

---
If this reply helps you, Karma would be appreciated.

jonaclough
Path Finder

You can prevent the dispatch of adhoc jobs to a SH using below setting in server.conf. Technote

[shclustering]
adhoc_searchhead = true
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...