Deployment Architecture

SHC cluster Label

locose
Path Finder

I’m trying to setup our Splunk DMC . I’m going through the setup instructions on the Splunk web site. I noticed 2 confusing instructions.

http://docs.splunk.com/Documentation/Splunk/6.3.3/DMC/Setclusterlabels
On this url, the instruction is to run splunk edit shcluster-config -shcluster_label on any of search head cluster member .

http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/SHCconfigurationoverview
On this url , the instruction is to run splunk edit shcluster-config -shcluster_label on each member of the search head cluster.

So should this command be executed on any of the search head cluster members or on each of the SHC members.

Thanks

Tags (2)
0 Karma

hexx
Splunk Employee
Splunk Employee

The first document is correct: You should be able to set the search-head cluster label from any member instance. You set it once and it will be propagated to all members.

Note that this does not indeed include the deployer, for which you will need to set the label manually as it is not really a member of the cluster but rather a supporting instance for it.

I have amended the documentation to make this clear.

0 Karma

ppeterson
Path Finder

I'm not sure if I understand the difference? If you are changing the label you need to change it on all of the search heads in the SHC in addition to having it consistent on the Deployer. A word of caution on 6.3.2, please ensure you have the config correct for the ./splunk init shcluster-config command - I had to re-configure the entire cluster to get this functioning properly. Additionally you will want to try to avoid using a "$" in the secret as when I got around to installing apps this appeared to cause issues in the CLI.

0 Karma

adauria_splunk
Splunk Employee
Splunk Employee

So that's the question - do it to a single member of the cluster, or do it to every member (plus the deployer, as you point out). You are saying you must do it to every member, but the doc shows it both ways. So if you're right, we need to change one of the docs.

Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...