All Apps and Add-ons

Okta Identity Cloud Add-on cluster deployment

tgrogan_stack
Explorer

I have recently deploy Splunk in a distributed environment with the following elements:

  • Management Server (SH Cluster Deployer, Deployment Server, Index Cluster Master)
  • Search Head Cluster (3 Search Heads)
  • Indexer Cluster (3 Indexers)

The add-on contains elements that should be deployed to the search heads as well as elements that should be deployed to the indexers, however, because some of these configurations also define the inputs, and the input is an API call to Okta API, I want to avoid the scenario where all three indexers are pulling the same data from the Okta API.

Is there any guidance from Okta regarding the best way for this add-on to be deployed in an environment with clustered search heads and indexers?

Should I simply install the add-on on a single search head and indexer rather than use the cluster bundle method? Or perhaps it would be better to utilize a Heavy Forwarder.

Any guidance is greatly appreciated.

 

Labels (2)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...