Deployment Architecture

Can same server be SH , indexer and console for splunk enterprise

Mad2
Observer

need to install the splunk enterprise and wanted to make SH and indexer , universal forwarder  same system , please advise

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

The only reason I can think of to try to do such thing would be to set up a small lab for learning Splunk in a bit more "distributed" setup than just an all-in-one server.

But in such case, I'd go for spinning up separate VMs and installing each component on a separate VM.

Also be prepared for a very very low performance.

gcusello
SplunkTrust
SplunkTrust

Hi @Mad2,

about Universal Forwarder, as @richgalloway said, you don't need it if you have a full Splunk instance, even if it's a lab installation.

About the opportunity to have Search Head, Indexer and Monitoring Console on the same server, it's possible if you have a stand alone Splunk Server , and to have it, you don't need to do nothing, only install Splunk.

If instead you have a distributed architecture, with more SHs and/or more indexers, it isn't possible: you must have dedicated systems for SHs and different dedicated systems for IDXs.

Monitoring Console could share the system with other roles, but not SHs, IDXs and Deployment Server (if you have to manage more than 50 clients).

Ciao.

Giuseppe

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Don't install multiple instances of Splunk on the same server as that invites trouble.  It can be done, but it requires and lot of customization.

There's no need to have a UF on the same server as a full instance of Splunk since the full instance can do everything a UF can do (and more).

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...