Deployment Architecture

How to configure search head clustering in multisite environment

Sourabhv05
Communicator

I had setup multisite cluster 6.2.1. Details of my Splunk environment are mentioned below

We have two sites
MasterNode : 1
Search Head : 2 search head in site 1 and 1 search head in site 2 .
Peers : 3 Peers at site 1 and 1 peers at site 2.

I am looking to setup search head clustering. Can i setup 1 search head cluster and include all search heads ( 2 from site 1 and 1 from site 2) or i had to setup two diffrent search head clusters ?

Please let me know the configurations to perfom the search head clustering based on above details.

regards,
Sourabh Varshney

Lowell
Super Champion

The docs say:

 Running a cluster across multiple sites is not currently supported. Search head clusters have been tested only with all members running on a single site.

Steve_G_
Splunk Employee
Splunk Employee

That restriction was removed with release 6.3. For current guidelines, see http://docs.splunk.com/Documentation/Splunk/6.5.2/DistSearch/SHCsystemrequirements#Search_head_clust...

0 Karma

mikaelbje
Motivator

Hmm, not supported/tested is one thing, but I'm curious whether it would work. I'll open a support case to get some more info. Thanks for the clarification.

0 Karma

Sourabhv05
Communicator

I have configured Search Head Clustering on Windows Servers and it is working fine with some limitations.

antonyhan
Path Finder

what limitations did you have please?
thanks.

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

Yes, You can set up a single SHC with nodes from 2 different sites. But keep in mind that if Site 1 is lost, then Site 2 won't be able to run any of your scheduled searches (you can still run your adhoc searches). This is due to majority node requirement in SHC.

Refer here

http://docs.splunk.com/Documentation/Splunk/6.2.1/DistSearch/Runtimeissues#Site_failure_can_prevent_...

http://docs.splunk.com/Documentation/Splunk/6.2.1/DistSearch/SHCarchitecture#Captain_election_proces...

Sourabhv05
Communicator

I am able to run the initialize command but while creating a captian by running bootstarp command

splunk bootstrap shcluster-captain -servers_list ":,:,..."

I am getting error as splunk does not recognize bootstarp. Please check command or take help.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...