Deployment Architecture

Possible to get the Unix App working on a 5.x Cluster?

gryz
Explorer

I'm looking to get the Unix App working on a Splunk 5.x cluster environment.

Anybody do this yet? Suggestions on how to do it...

Thanks!

Tags (3)
0 Karma

bmacias84
Champion

@gryz,

I familar witht he process but, the best I can do for you is point you to the documentation for each component. The setup will vary depending on your Operational requirement and budget. Be aware that 5.x Clustering duplicates the all indices on your Indexer.

Additional Reading:

Enableclustersindetail

Configurethemaster

Aboutdeploymentserver

Whatisdistributedsearch

Configuredistributedsearch

Hope this helps or gets you started. Dont forget to thumbs up or accept answers that help. Cheers,

0 Karma

gryz
Explorer

Yes, I think what you have described is what I want.

0 Karma

bmacias84
Champion

So what you want is Distributed Search to search knowledge objects on your search head and Clustering for your indexers. Additionally you will want to use the Deployment server or Puppet to deploy your apps like the Nix app.

0 Karma

gryz
Explorer

Both I suppose.

The indexers will need the os index on them and the Search head will need the app. I'm using the TA for *nix on the forwarders.

0 Karma

bmacias84
Champion

Are talking about your search nix app or are you talking about your indexers?

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...