Deployment Architecture

Adding new SH cluster to existing splunk setup.

sajeshpp
Path Finder

Currently we have 1 multisite indexing cluster, 1 multisite search head cluster, a deployer and a master node.
Planning to add one more search head cluster which will have same configuration as existing SH cluster.
So we will be using same deployer and indexing cluster with this new cluster.
1. What are the configuration changes required in deployer If it manage multiple SH clusters. ?
2.What will be the deference in existing SH member and new cluster members ?
I could not find any splunk docs to find what is the difference in deployer configuration when it mange single cluster and multiple clusters.

Basically the requirement will be to have a splunk setup with
1 Multisite Indexing cluster, 2 Multisite SH cluster, 1 Master node and a deployer.

Tags (1)
0 Karma

somesoni2
Revered Legend

A deployer can't manage multiple SH cluster. You would need a separate deployer node. It however, can co-exist with your indexer cluster-master node, provided there is not too much load on cluster-master and it has sufficient h/w resource. So you can either add a new deployer node OR setup your cluster master as deployer for new SHC.

0 Karma

sajeshpp
Path Finder

As per splunk documentation they says you can use same deployer for all clusters if it employ same configuration.
"
Deploy to multiple clusters
The deployer sends the same configuration bundle to all cluster members that it services. Therefore, if you have multiple search head clusters, you can use the same deployer for all the clusters only if the clusters employ exactly the same configurations, apps, and so on.

If you anticipate that your clusters might need different configurations over time, set up a separate deployer for each cluster "

http://docs.splunk.com/Documentation/Splunk/6.6.2/DistSearch/PropagateSHCconfigurationchanges#Deploy...

But I dont see the deployer configuration differences when it serves for single cluster and multiple cluster in splunk documentation.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...