Deployment Architecture

How to migrate Single distributed search head to Search Head cluster with 3 members?

siva_cg
Path Finder

Hi All,

We are planning to migrate Single distributed search head to Search Head cluster with 3 members and would like to use existing Cluster Master which also acts as License Master and Deployment server (around 20 Universal Forwarders) as Deployer for Search Head Cluster members. Is it a good idea to run the environment like this? It would be very helpful if you have any suggestions. Thanks in advance.

0 Karma
1 Solution

adonio
Ultra Champion

hello there,

good is a relative term.
there are also many other variables to consider, such as:
what OS are you running on?
How many indexers?
How many indexes? and how many buckets are replicated per hour?
how much data is being indexed daily?
What are your VM specs? CPU, Memory?
in any case, although splunk best practices to have a single machine to each role (license Master, Cluster Master, Deployer, Deployment Server) and Splunk says not to have Deployment Server with Cluster Master under any circumstances (which you already doing), i have seen many deployments with shared splunk server roles
read here all the way:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Indexer/Systemrequirements
elaborated answer here:
https://answers.splunk.com/answers/380825/possible-combinations-of-splunk-instances-with-dif.html

to sum it up, it is a poor practice, but it will work

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hello there,

good is a relative term.
there are also many other variables to consider, such as:
what OS are you running on?
How many indexers?
How many indexes? and how many buckets are replicated per hour?
how much data is being indexed daily?
What are your VM specs? CPU, Memory?
in any case, although splunk best practices to have a single machine to each role (license Master, Cluster Master, Deployer, Deployment Server) and Splunk says not to have Deployment Server with Cluster Master under any circumstances (which you already doing), i have seen many deployments with shared splunk server roles
read here all the way:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Indexer/Systemrequirements
elaborated answer here:
https://answers.splunk.com/answers/380825/possible-combinations-of-splunk-instances-with-dif.html

to sum it up, it is a poor practice, but it will work

hope it helps

0 Karma

siva_cg
Path Finder

Hi @adonio,

Thank you for the feedback. We have very less indexing rate (ingesting 10GB/day) in that environment and mainly used for testing purpose and want to make that environment identical to production.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...