Deployment Architecture

If we enable DMC in search head in Production environment is there any impact on the searches

pha
New Member

If we enable DMC in Search head in a Production environment is there any impact on the searches.

I have a lot of historical searches are running on it.
Is it the Best practice to do?

0 Karma

woodcock
Esteemed Legend

Just enabling it will not cause any problems BUT, if you fully configure it and add non-indexers as search peers (which you have to do to get the full features/data), you will be creating potential search results data duplication, search delays, incorrect warnings and errors reported in the UI and other minor problems. None of these are serious, but it is still a poor practice.

0 Karma

pha
New Member

is there any way I can roll back to the standalone mode.

0 Karma

pha
New Member

Because it has 84 search peers and 90 cluster master

0 Karma

adonio
Ultra Champion

click settingdg dropdown -> general settings -> on the top line (your DMC instance name) on the right hand side click edit -> disable. notice it says "disabled" with a little red X
Do not click "Apply All Changes" afterwards

0 Karma

adonio
Ultra Champion

best will be to have a dedicated Search Head for the DMC (now MC)
read here:
https://docs.splunk.com/Documentation/Splunk/7.1.1/DMC/WheretohostDMC
and here more specific to your question:
https://docs.splunk.com/Documentation/Splunk/7.1.1/DMC/WheretohostDMC#Why_not_to_host_the_console_on...

hope it helps

pha
New Member

Q) I have enabled DMC in distributed mode is there a way I can come back to standalone mode.

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...