Deployment Architecture

How to migrate Single distributed search head to Search Head cluster with 3 members?

siva_cg
Path Finder

Hi All,

We are planning to migrate Single distributed search head to Search Head cluster with 3 members and would like to use existing Cluster Master which also acts as License Master and Deployment server (around 20 Universal Forwarders) as Deployer for Search Head Cluster members. Is it a good idea to run the environment like this? It would be very helpful if you have any suggestions. Thanks in advance.

0 Karma
1 Solution

adonio
Ultra Champion

hello there,

good is a relative term.
there are also many other variables to consider, such as:
what OS are you running on?
How many indexers?
How many indexes? and how many buckets are replicated per hour?
how much data is being indexed daily?
What are your VM specs? CPU, Memory?
in any case, although splunk best practices to have a single machine to each role (license Master, Cluster Master, Deployer, Deployment Server) and Splunk says not to have Deployment Server with Cluster Master under any circumstances (which you already doing), i have seen many deployments with shared splunk server roles
read here all the way:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Indexer/Systemrequirements
elaborated answer here:
https://answers.splunk.com/answers/380825/possible-combinations-of-splunk-instances-with-dif.html

to sum it up, it is a poor practice, but it will work

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hello there,

good is a relative term.
there are also many other variables to consider, such as:
what OS are you running on?
How many indexers?
How many indexes? and how many buckets are replicated per hour?
how much data is being indexed daily?
What are your VM specs? CPU, Memory?
in any case, although splunk best practices to have a single machine to each role (license Master, Cluster Master, Deployer, Deployment Server) and Splunk says not to have Deployment Server with Cluster Master under any circumstances (which you already doing), i have seen many deployments with shared splunk server roles
read here all the way:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Indexer/Systemrequirements
elaborated answer here:
https://answers.splunk.com/answers/380825/possible-combinations-of-splunk-instances-with-dif.html

to sum it up, it is a poor practice, but it will work

hope it helps

0 Karma

siva_cg
Path Finder

Hi @adonio,

Thank you for the feedback. We have very less indexing rate (ingesting 10GB/day) in that environment and mainly used for testing purpose and want to make that environment identical to production.

0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...