Deployment Architecture

Need a help to setup distributed monitoring console

santhanam95
Observer

Hi All,

We are planning to build on separate Linux server for DMC and we have below components.

Search Head cluster - 2 search head cluster member 

Deployer/Cluster Master/License master - 1 server

Index cluster - 3 Indexer

Deployment Server - 1server

What are hardware requirement for DMC and configuration steps to monitor the rest of components(7 servers) in DMC.

Please share us the plan.

Thank You!

 

With Regards,

Santhana Bharathi

 

 

 

Tags (1)
0 Karma

MaverickT
Communicator

Just one addon to your arhitecture. Search head cluster should have at least 3 members. Otherwise it won't be able to elect the search head captain. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The hardware requirements for Splunk are at https://docs.splunk.com/Documentation/Splunk/8.0.4/Capacity/Referencehardware#Dedicated_search_head (the MC is just a search head), although you could get away with a much smaller instance.

The steps for setting up a Monitoring Console are at https://docs.splunk.com/Documentation/Splunk/8.0.4/DMC/Deploymentsetupsteps

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...