Hi!
This is our first time to deploy Splunk Enterprise environment.
So, I would like to confirm the composition of our servers for Splunk Enterprise.
[Question]
Is it possible to deploy Splunk Enterprise environment with the following servers?
1. Search Head (1 server)
2. Indexer (2 servers with clustering)
3. Deployment server and License Master (1server)
4. Cluster Master(1server)
We will use this environment for 1st step of Splunk utilize.
(This is an environment where the current status of the 1st step can be created while waiting for the 2nd step hardware to be built.)
We will create the environment for 2nd step. If the 2nd step environment is deployed, we will change connection setting of universal forwarder from 1st step environment to 2nd step environment.
Best, Regards.
Hi @tsyasuo,
As a first step seems fine with missing Monitoring Console. You can run Monitoring Console in Cluster Master instance in first step. You can consider moving Monitoring Console to separate instance on second step.
You can check below pdf for Splunk Validated Architectures. Your first step is like C1.
https://www.splunk.com/pdfs/technical-briefs/splunk-validated-architectures.pdf
Hi @scelikok ,
Thank you for your reply. This answer will help me a lot.
I will proceed with that servers and settings.
Best Regards.