Archive

create/add splunk search head cluster to existing index cluster (with working search heads)

Path Finder

[env]
centos 7, splunk enterprise 6.4.1
4x search heads (-mode searchhead -master_uri cluster_master) [2 heads are set to be decommissioned]
3x clustered index peers (cluster master) <- multi site capable, 1 site live for now
2x heavy forwarders
load balanced reverse proxy serving search head pool url access for users

question:
i am in the process of researching implementing a search head cluster in the current model (see [env] above) and have been looking at the following documentation; http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCdeploymentoverview

1: am i able to use 3 search head nodes that are already pointing the the back-end index cluster and then just run the commands to add these members to the search head cluster (and elect a captain) <- also add the deployer role to the index cluster master?

2: if no to No.1 do I create 3x new nodes as search heads, then create the search head cluster and a separate deployer node - if so, how best do i point these to use the index cluster peers?

I'm going to running this up in a lab, so I will update progress but if anyone has any initial guidance/pointers, that would be very much appreciated.

Thx
Bry

Tags (1)
0 Karma
1 Solution

Path Finder

http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

followed the guide above and results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

View solution in original post

Path Finder

http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

followed the guide above and results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

View solution in original post

Path Finder

also saw this link in the document about integrating shc with an idxc; http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

0 Karma

Path Finder

looking more like i create the shc then add to the idx cluster.

0 Karma

Path Finder

i have a multi-node splunk lab setup now (to emulate my ^^^[env]). i will post my findings here once i have fully tested the options.

0 Karma

Path Finder

ok, results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

0 Karma