Deployment Architecture

Search Head on Splunk Cloud

cpraz_ord
Explorer

Hi...I believe Splunk Cloud has 3 indexers, what about Search Heads? If there multiple Search Heads, does the ES app get propagated across SH clusters & Index clusters?

Tags (1)

pgreer_splunk
Splunk Employee
Splunk Employee

A base build is 1-3 (being one search head and 3x indexers). Of course, each build is sized to a customer's initial target ingest rate, data retention, etc.

If a customer is large enough (enough concurrent users) a search head might initially be deployed. Otherwise they are single search heads.

You are correct, if there is a premium app purchased (such as ES or ITSI) that warrants it's own search head, then a second (or more) search head will be deployed. Typically a base search head is at a canonical name https://.splunkcloud.com where the additional ES search head would reside at https://es-.splunkcloud.com.

Again, that being said, if the size of the customer, concurrent users, search load, etc. - then a search head cluster might be deployed (for the ad-hoc searching purposes or independently for ES).

As for propagation across search heads and indexers, it depends on the app. If the app requires indexing time props/transforms then there will be configuration pieces on the indexers. If the app only has search time props/transforms then it may only reside on the search head (or search heads if in a search head cluster).

Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...