Deployment Architecture

How to migrate Single distributed search head to Search Head cluster with 3 members?

siva_cg
Path Finder

Hi All,

We are planning to migrate Single distributed search head to Search Head cluster with 3 members and would like to use existing Cluster Master which also acts as License Master and Deployment server (around 20 Universal Forwarders) as Deployer for Search Head Cluster members. Is it a good idea to run the environment like this? It would be very helpful if you have any suggestions. Thanks in advance.

0 Karma
1 Solution

adonio
Ultra Champion

hello there,

good is a relative term.
there are also many other variables to consider, such as:
what OS are you running on?
How many indexers?
How many indexes? and how many buckets are replicated per hour?
how much data is being indexed daily?
What are your VM specs? CPU, Memory?
in any case, although splunk best practices to have a single machine to each role (license Master, Cluster Master, Deployer, Deployment Server) and Splunk says not to have Deployment Server with Cluster Master under any circumstances (which you already doing), i have seen many deployments with shared splunk server roles
read here all the way:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Indexer/Systemrequirements
elaborated answer here:
https://answers.splunk.com/answers/380825/possible-combinations-of-splunk-instances-with-dif.html

to sum it up, it is a poor practice, but it will work

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hello there,

good is a relative term.
there are also many other variables to consider, such as:
what OS are you running on?
How many indexers?
How many indexes? and how many buckets are replicated per hour?
how much data is being indexed daily?
What are your VM specs? CPU, Memory?
in any case, although splunk best practices to have a single machine to each role (license Master, Cluster Master, Deployer, Deployment Server) and Splunk says not to have Deployment Server with Cluster Master under any circumstances (which you already doing), i have seen many deployments with shared splunk server roles
read here all the way:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Indexer/Systemrequirements
elaborated answer here:
https://answers.splunk.com/answers/380825/possible-combinations-of-splunk-instances-with-dif.html

to sum it up, it is a poor practice, but it will work

hope it helps

0 Karma

siva_cg
Path Finder

Hi @adonio,

Thank you for the feedback. We have very less indexing rate (ingesting 10GB/day) in that environment and mainly used for testing purpose and want to make that environment identical to production.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...