Deployment Architecture

Need help setting up a Splunk 6.2.3 Distributed Environment

Magnus_001
Explorer

Hello,

We are in the process of setting up a Spunk 6.2.3 distributed environment with a dedicated search head, indexer and deployment server. We installed enterprise Splunk on all three servers and applied the license but not sure what to do next. Is there a way to configure the servers for their specific roles and remove unnecessary ones? We couldn't find step-by-step instructions in the Splunk documentation. Thanks!

0 Karma

vnguyen46
Contributor

I have the same question and been looking for an answer from books, training courses, and community, but no luck. Basically, it's how to setup a Splunk distributed environment.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

You can find step-by-step instructions in the Distributed Search manual.

http://docs.splunk.com/Documentation/Splunk/6.2.3/DistSearch/Whatisdistributedsearch

You can also find wizards, warlocks, trolls, and goblins in the #splunk IRC channel on EFnet. We are more than happy to help you out in person, and to take your gold.

*gold = not real gold. No one does that anymore. We won't take anything. But you will leave satisfied.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

[Puzzles] Solve, Learn, Repeat: Family Trees

This puzzle (first published here is based on finding grandparents and grandchildren (inspired by a question ...