Deployment Architecture

Need steps for configuring deployment server in indexer server.

pradeepkumar_n0
New Member

Hi Team,

I am having a cluster setup with the following architecture.

1) One Splunk Manager.
2) One Search Head
3) Two Peer nodes (i.e Two Indexers)
4) Total 50 Linux and Windows Forwarder servers.

I am trying to setup a deployment server in one of the indexer nodes. Could someone please let us know, whether we can use one of indexer node as deployment server or we need to have a dedicated server.

My requirement is to maintain all of the forwarders inputs.conf and outputs.conf from the deployment server.

I have gone through below URLS. Could some one suggest and provide me the actual steps for configuring deployment server and also configuration steps need to be performed at forwarders end.

1)http://docs.splunk.com/Documentation/Splunk/6.0.2/Updating/Planadeployment
2)http://answers.splunk.com/answers/12384/hardware-requirements-for-deployment-server-in-large-deploym...
3)http://docs.splunk.com/Documentation/Splunk/6.0.2/Updating/Calculatedeploymentserverperformance

Regards,
Pradeep.

Tags (2)
0 Karma

lukejadamec
Super Champion

Yes, you can use an indexer, but you a little over the recommended limit. You will have to review your server hardware and workload to see if it can support the extra work. If you find that after you configure the deployment server that it should be on it's own server, then the configuration can be relocated to a new server.

You can manage the inputs.conf and outputs.conf, but you will need at least two apps, one for windows and one for unix. If all of your windows and unix configs are not exactly the same, then you will need additional serverclasses for them.

The quick 'developer minded' guide for setting up and troubleshooting a deployment server can be found here:
http://wiki.splunk.com/Deploy:DeploymentServer

The Splunk documentation for configuring a deployment server can be found here:
http://docs.splunk.com/Documentation/Splunk/latest/Updating/Aboutdeploymentserver

Take the time to read and understand the material. A deployment server is very handy, but it must be configured correctly and each configuration is specific to the deployment - there is no magic plan that works for everyone.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...