Deployment Architecture

Is there a limit to how many Search Heads can be part of a Cluster?

katelynengel
Explorer

Is there a limit to how many Search Heads can be part of a Cluster?

We have a fairly large deployment and I wanted to know if there is a max limit of the amount of SH's that can be part of any one cluster.

1 Solution

hexx
Splunk Employee
Splunk Employee

I believe that the maximum number of members currently supported in a search-head cluster is 50.

I am not finding this documented in the expected location, so I am going to ask for this to be corrected.

View solution in original post

hexx
Splunk Employee
Splunk Employee

By the way, just to disambiguate: Are you talking about an indexer cluster, a search-head cluster or a combination of both?

katelynengel
Explorer

I meant Search Head Cluster but I would also be interested in the limit for an Indexer Cluster.

0 Karma

hexx
Splunk Employee
Splunk Employee

I don't think that we have identified a limit in the number of search-heads that can be attached to an indexer cluster. Of course, if those search-heads are going to be members of a search-head cluster, you'd want to keep that number at a maximum of 50 if you want to remain within the supported boundaries.

0 Karma

muebel
SplunkTrust
SplunkTrust

Hi katelynengel, I don't know if there is a theoretical limit to the amount of members in a cluster (close analysis of the raft consensus algorithm that is the foundation for the cluster might reveal that https://raft.github.io/ ), there is a practical limit based on latency between members, and the time it takes for changes to propagate.

If you have anything under a couple dozen members you should probably be fine. If you are planning on implementing a cluster of something like 50, you should let Splunk know as they will probably be very interested to hear of the results.

Let me know what you think 😄

hexx
Splunk Employee
Splunk Employee

I believe that the maximum number of members currently supported in a search-head cluster is 50.

I am not finding this documented in the expected location, so I am going to ask for this to be corrected.

katelynengel
Explorer

Thanks! I'll pass along to my team. 🙂

0 Karma

lguinn2
Legend

Now documented here:
http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/SHCsystemrequirements

At 7.0.2, the max is 100 search heads in a cluster; Thanks @hexx

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...