Deployment Architecture

How to migrate Single distributed search head to Search Head cluster with 3 members?

siva_cg
Path Finder

Hi All,

We are planning to migrate Single distributed search head to Search Head cluster with 3 members and would like to use existing Cluster Master which also acts as License Master and Deployment server (around 20 Universal Forwarders) as Deployer for Search Head Cluster members. Is it a good idea to run the environment like this? It would be very helpful if you have any suggestions. Thanks in advance.

0 Karma
1 Solution

adonio
Ultra Champion

hello there,

good is a relative term.
there are also many other variables to consider, such as:
what OS are you running on?
How many indexers?
How many indexes? and how many buckets are replicated per hour?
how much data is being indexed daily?
What are your VM specs? CPU, Memory?
in any case, although splunk best practices to have a single machine to each role (license Master, Cluster Master, Deployer, Deployment Server) and Splunk says not to have Deployment Server with Cluster Master under any circumstances (which you already doing), i have seen many deployments with shared splunk server roles
read here all the way:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Indexer/Systemrequirements
elaborated answer here:
https://answers.splunk.com/answers/380825/possible-combinations-of-splunk-instances-with-dif.html

to sum it up, it is a poor practice, but it will work

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hello there,

good is a relative term.
there are also many other variables to consider, such as:
what OS are you running on?
How many indexers?
How many indexes? and how many buckets are replicated per hour?
how much data is being indexed daily?
What are your VM specs? CPU, Memory?
in any case, although splunk best practices to have a single machine to each role (license Master, Cluster Master, Deployer, Deployment Server) and Splunk says not to have Deployment Server with Cluster Master under any circumstances (which you already doing), i have seen many deployments with shared splunk server roles
read here all the way:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Indexer/Systemrequirements
elaborated answer here:
https://answers.splunk.com/answers/380825/possible-combinations-of-splunk-instances-with-dif.html

to sum it up, it is a poor practice, but it will work

hope it helps

0 Karma

siva_cg
Path Finder

Hi @adonio,

Thank you for the feedback. We have very less indexing rate (ingesting 10GB/day) in that environment and mainly used for testing purpose and want to make that environment identical to production.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...