Deployment Architecture

Should the master node be a license slave?

dpham36
New Member

I have 1 master node, 2 peer nodes (indexers), and a separate search head. I've set up the search head as the license master (not the master node, as recommended in the documentation), and currently the 2 peer nodes (indexers) are license slaves that point to the new license master. Should I also configure the master node as a license slave?

Tags (1)
0 Karma

lguinn2
Legend

The master node must be a license slave. It must also be in the same pool as the indexers in the cluster.

0 Karma

dpham36
New Member

Ok great, that's what I thought (that it must be a license slave). As for the same pool - what if the indexers are in different pools? In my set up, they are all in the default 'auto_generated_pool_enterprise' (since I have the Enterprise license, and since I haven't created any custom pools), but I understand that you can set up different pools for different indexers to manage how much license volume each one is allowed to use per day...

0 Karma

dpham36
New Member

NOTE - From the documentation, I understand also that 'Any host in your Splunk Enterprise infrastructure that performs indexing must be licensed to do so. You can either run a standalone indexer with a license installed locally, or you can configure one of your Splunk Enterprise instances as a license master and set up a license pool from which other indexers, configured as license slaves, can draw. ' Will the master node be doing any indexing (meaning it will have to be turned into a license slave)?

0 Karma

somesoni2
Revered Legend

Are you forwarding logs, including _internal logs from Master node to your Indexers? If yes than no local indexing will be happening, so you set the master node with Forwarder license. Though, setting it as license slave would not hurt.

0 Karma

dpham36
New Member

I only planned on forwarding logs to the indexers (index cluster) from separate servers that have the Splunk Universal Forwarder installed. Unless the master node automatically forwards internal logs to it's peer nodes (the indexers), then no, I am not currently forwarding _internal logs to the indexers from the master node.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...