I have a single search head and 2 indexers (not clustered) and about 100 universal forwarders that point to either indexer in case one indexer is offline.
I have Monitoring of Java Machines (JMX) loaded on only one indexer (not ideal), but is working.
I have an application using the ReST interface sending data to the other indexer (not ideal), but is working.
I now want to install DB Connect into this existing infrastructure. I am using it only to read tables on database (no writes to DB) and could use it later for database lookups.
Thanks
Hi,
I would run DB Connect on the search head in this environment and not worry about resource pool. If you want to have the configuration be more fault tolerant and you have more hardware, you could go to search head clustering and the connections will make it through a search head failure. The resource pool thing is more about scaling than fault tolerance.
I am running Splunk 6.1.2 on Search head and both indexers.