Deployment Architecture

How to configure search head clustering in multisite environment

Sourabhv05
Communicator

I had setup multisite cluster 6.2.1. Details of my Splunk environment are mentioned below

We have two sites
MasterNode : 1
Search Head : 2 search head in site 1 and 1 search head in site 2 .
Peers : 3 Peers at site 1 and 1 peers at site 2.

I am looking to setup search head clustering. Can i setup 1 search head cluster and include all search heads ( 2 from site 1 and 1 from site 2) or i had to setup two diffrent search head clusters ?

Please let me know the configurations to perfom the search head clustering based on above details.

regards,
Sourabh Varshney

Lowell
Super Champion

The docs say:

 Running a cluster across multiple sites is not currently supported. Search head clusters have been tested only with all members running on a single site.

Steve_G_
Splunk Employee
Splunk Employee

That restriction was removed with release 6.3. For current guidelines, see http://docs.splunk.com/Documentation/Splunk/6.5.2/DistSearch/SHCsystemrequirements#Search_head_clust...

0 Karma

mikaelbje
Motivator

Hmm, not supported/tested is one thing, but I'm curious whether it would work. I'll open a support case to get some more info. Thanks for the clarification.

0 Karma

Sourabhv05
Communicator

I have configured Search Head Clustering on Windows Servers and it is working fine with some limitations.

antonyhan
Path Finder

what limitations did you have please?
thanks.

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

Yes, You can set up a single SHC with nodes from 2 different sites. But keep in mind that if Site 1 is lost, then Site 2 won't be able to run any of your scheduled searches (you can still run your adhoc searches). This is due to majority node requirement in SHC.

Refer here

http://docs.splunk.com/Documentation/Splunk/6.2.1/DistSearch/Runtimeissues#Site_failure_can_prevent_...

http://docs.splunk.com/Documentation/Splunk/6.2.1/DistSearch/SHCarchitecture#Captain_election_proces...

Sourabhv05
Communicator

I am able to run the initialize command but while creating a captian by running bootstarp command

splunk bootstrap shcluster-captain -servers_list ":,:,..."

I am getting error as splunk does not recognize bootstarp. Please check command or take help.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...