Deployment Architecture

Search Head Clustering : Preferred approach Odd number or Even number per site?

koshyk
Super Champion

folks,
We have two sites and we host 8 Search Heads (4 per site) all clustered with 16 indexers. We need to have a non-clustered SearchHead(SH) for sandbox purposes connected to same indexers

My colleague is suggesting its better to have an odd + even setup in SH (ie. 3x + 4y + 1 standalone) as SH captain works on odd/even configuration better. But my view is to have (4x + 4y + 1 standalone) for consistency and maintainability purposes. (ps: company can sponsor 2 SH's extra, budget is not the real problem)

Any suggestions on above?

0 Karma
1 Solution

javiergn
Super Champion

Take a look at this:

http://docs.splunk.com/Documentation/Splunk/6.3.1511/DistSearch/DeploymultisiteSHC#Important_conside...

If you want my personal opinion: go for 3 + 4. You only have 2 sites so this would be my preference. If you had 3 sites I would go for 9 Search Heads because majority is 5 and therefore you can afford losing one site completely.

Also isn't the Indexer-Search Head ratio a bit low? 2 indexers per Search Head is not too much. Is there any reason you need so many Search Heads in your deployment?
See this:

http://docs.splunk.com/Documentation/Splunk/6.2.0/Capacity/Referencehardware#Ratio_of_indexers_to_se...
http://docs.splunk.com/Documentation/Splunk/latest/Capacity/Summaryofperformancerecommendations

EDIT: your idea about the extra search head is good too. You could also use it for testing purposes or even as a staging server should you decided to get Enterprise Security.

View solution in original post

javiergn
Super Champion

Take a look at this:

http://docs.splunk.com/Documentation/Splunk/6.3.1511/DistSearch/DeploymultisiteSHC#Important_conside...

If you want my personal opinion: go for 3 + 4. You only have 2 sites so this would be my preference. If you had 3 sites I would go for 9 Search Heads because majority is 5 and therefore you can afford losing one site completely.

Also isn't the Indexer-Search Head ratio a bit low? 2 indexers per Search Head is not too much. Is there any reason you need so many Search Heads in your deployment?
See this:

http://docs.splunk.com/Documentation/Splunk/6.2.0/Capacity/Referencehardware#Ratio_of_indexers_to_se...
http://docs.splunk.com/Documentation/Splunk/latest/Capacity/Summaryofperformancerecommendations

EDIT: your idea about the extra search head is good too. You could also use it for testing purposes or even as a staging server should you decided to get Enterprise Security.

koshyk
Super Champion

thanks for your input and links. voting up. (Will accept by end of this week, just wanted to see if any other opinion comes as well)

0 Karma

somesoni2
Revered Legend

Another reason to go with 3+4 is that with 7 SH, the majority number is 4. With 8 SH, the majority number required will be 5, so you have to use 5 + 3 (+ 1 standalone) combination to allow primary site (with 5) to be available in case secondary site is down (and you loose your consistency point anyways).

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...