Deployment Architecture

If we enable DMC in search head in Production environment is there any impact on the searches

pha
New Member

If we enable DMC in Search head in a Production environment is there any impact on the searches.

I have a lot of historical searches are running on it.
Is it the Best practice to do?

0 Karma

woodcock
Esteemed Legend

Just enabling it will not cause any problems BUT, if you fully configure it and add non-indexers as search peers (which you have to do to get the full features/data), you will be creating potential search results data duplication, search delays, incorrect warnings and errors reported in the UI and other minor problems. None of these are serious, but it is still a poor practice.

0 Karma

pha
New Member

is there any way I can roll back to the standalone mode.

0 Karma

pha
New Member

Because it has 84 search peers and 90 cluster master

0 Karma

adonio
Ultra Champion

click settingdg dropdown -> general settings -> on the top line (your DMC instance name) on the right hand side click edit -> disable. notice it says "disabled" with a little red X
Do not click "Apply All Changes" afterwards

0 Karma

adonio
Ultra Champion

best will be to have a dedicated Search Head for the DMC (now MC)
read here:
https://docs.splunk.com/Documentation/Splunk/7.1.1/DMC/WheretohostDMC
and here more specific to your question:
https://docs.splunk.com/Documentation/Splunk/7.1.1/DMC/WheretohostDMC#Why_not_to_host_the_console_on...

hope it helps

pha
New Member

Q) I have enabled DMC in distributed mode is there a way I can come back to standalone mode.

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...