Deployment Architecture

Impact of shutting down some splunk roles for a day?

jdmclemore
Path Finder

I have a 5 node indexer cluster and a 3 node SHC which are all physical servers, but the rest are VMs (Deployment server, License Server, Deployer, Master Cluster node, and DMC).

My VMs will be migrating to another network and will require downtime of about a day. I would like to leave the search heads and indexers up to continue collecting data during the outage. Is this possible? What impact will shutting down all those other servers have?

Tags (1)
0 Karma
1 Solution

lguinn2
Legend

If properly configured, the search heads and indexers should continue to operate for 24 hours without the other servers online.

That said, it would be much better if the outage was shorted. For example, when the Cluster Master Node comes back online, the cluster will need to "catch up" on the missed replication. Therefore, the longer the outage, the longer the "recovery."

I would prioritize the servers in this order:
Master Node
Monitoring Console
License Master
Deployment Server
Deployer

View solution in original post

0 Karma

lguinn2
Legend

If properly configured, the search heads and indexers should continue to operate for 24 hours without the other servers online.

That said, it would be much better if the outage was shorted. For example, when the Cluster Master Node comes back online, the cluster will need to "catch up" on the missed replication. Therefore, the longer the outage, the longer the "recovery."

I would prioritize the servers in this order:
Master Node
Monitoring Console
License Master
Deployment Server
Deployer

0 Karma

jdmclemore
Path Finder

Thank you!

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...