Deployment Architecture

SHC cluster Label

locose
Path Finder

I’m trying to setup our Splunk DMC . I’m going through the setup instructions on the Splunk web site. I noticed 2 confusing instructions.

http://docs.splunk.com/Documentation/Splunk/6.3.3/DMC/Setclusterlabels
On this url, the instruction is to run splunk edit shcluster-config -shcluster_label on any of search head cluster member .

http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/SHCconfigurationoverview
On this url , the instruction is to run splunk edit shcluster-config -shcluster_label on each member of the search head cluster.

So should this command be executed on any of the search head cluster members or on each of the SHC members.

Thanks

Tags (2)
0 Karma

hexx
Splunk Employee
Splunk Employee

The first document is correct: You should be able to set the search-head cluster label from any member instance. You set it once and it will be propagated to all members.

Note that this does not indeed include the deployer, for which you will need to set the label manually as it is not really a member of the cluster but rather a supporting instance for it.

I have amended the documentation to make this clear.

0 Karma

ppeterson
Path Finder

I'm not sure if I understand the difference? If you are changing the label you need to change it on all of the search heads in the SHC in addition to having it consistent on the Deployer. A word of caution on 6.3.2, please ensure you have the config correct for the ./splunk init shcluster-config command - I had to re-configure the entire cluster to get this functioning properly. Additionally you will want to try to avoid using a "$" in the secret as when I got around to installing apps this appeared to cause issues in the CLI.

0 Karma

adauria_splunk
Splunk Employee
Splunk Employee

So that's the question - do it to a single member of the cluster, or do it to every member (plus the deployer, as you point out). You are saying you must do it to every member, but the doc shows it both ways. So if you're right, we need to change one of the docs.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...