Deployment Architecture

Need help setting up a Splunk 6.2.3 Distributed Environment

Magnus_001
Explorer

Hello,

We are in the process of setting up a Spunk 6.2.3 distributed environment with a dedicated search head, indexer and deployment server. We installed enterprise Splunk on all three servers and applied the license but not sure what to do next. Is there a way to configure the servers for their specific roles and remove unnecessary ones? We couldn't find step-by-step instructions in the Splunk documentation. Thanks!

0 Karma

vnguyen46
Contributor

I have the same question and been looking for an answer from books, training courses, and community, but no luck. Basically, it's how to setup a Splunk distributed environment.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

You can find step-by-step instructions in the Distributed Search manual.

http://docs.splunk.com/Documentation/Splunk/6.2.3/DistSearch/Whatisdistributedsearch

You can also find wizards, warlocks, trolls, and goblins in the #splunk IRC channel on EFnet. We are more than happy to help you out in person, and to take your gold.

*gold = not real gold. No one does that anymore. We won't take anything. But you will leave satisfied.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...