Deployment Architecture

How to move the SHC - deployer to another host?

Glasses2
Communicator

Hi, 

Unfortunately I inherited a Splunk deployment where the previous admin co-located multiple roles to one Splunk host.   The admin put Deployment Server, SHC Deployer, and Monitoring Console roles all on a single box (on prem).  In order to update the Deployment Server, Support told me I need to first remove the MC and Deployer roles.   I can move the MC no problem, but moving the SHC Deployer is causing some concern.   The deployer is set to the standard "merge_to_default" but I not sure how to copy over the files to the new deployer.  I know I need to make sure all the apps on the current get moved over, but what about the local settings created by the user?  

 Support says having DS and Deployer roles on same box is not supported, which I agree, but I am not getting any guidance from them.

Any advice is greatly appreciated. 

 

Thank you

 

 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Any local settings by users should be on the SHC member nodes rather than the Deployer and so would not be a factor in moving the Deployer.  It should be a matter of copying $SPLUNK_HOME/etc/shcluster to the new server.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Any local settings by users should be on the SHC member nodes rather than the Deployer and so would not be a factor in moving the Deployer.  It should be a matter of copying $SPLUNK_HOME/etc/shcluster to the new server.

---
If this reply helps you, Karma would be appreciated.

Glasses2
Communicator

@richgalloway 

Thanks for the reply, that was my concern, I didn't want to lose or mess up the local settings...

So from what you said, there is not any real concern of losing or overwriting anything locally set on the SHC members...

IF you have any other advice or docs you can point me to regarding this endeavor, greatly appreciated!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...