Deployment Architecture

Should we use deployment server for forwarders with index clustering?

sachinbansal
New Member

Hi,

Suppose we have index clustering implemented so can we use deployment server for forwarders?

Regards,
Sachin

Tags (1)
0 Karma
1 Solution

HiroshiSatoh
Champion

The use of index clusters and deployment servers is completely unrelated. Is it a question of wanting to have the indexer and the deployment server that make up the index cluster coexist?

Or is it a question of setting the forwarder to a clustered indexer?

View solution in original post

HiroshiSatoh
Champion

The use of index clusters and deployment servers is completely unrelated. Is it a question of wanting to have the indexer and the deployment server that make up the index cluster coexist?

Or is it a question of setting the forwarder to a clustered indexer?

sachinbansal
New Member

@HiroshiSatoh - Index clustering is already there for indexers but we do not have any centralised server to control configs on all the forwarders. So can we use deployment server here to centrally manage configs of all forwarders.
In my previous question i wanted to ask that is it recommendable to use deployment server for forwarder's management whenwe have index cluster for indexers.
I am not whether it is related or not but just wanted ask that there wont be any issue with using deployment server for forwarders and index cluster for indexers in same environment?

0 Karma

HiroshiSatoh
Champion

There is no problem using a deployment server in an index cluster environment.

If you manage forwarders on a Splunk server regardless of the index cluster, you must use an deployment server.

0 Karma

sachinbansal
New Member

Okay thankyou 🙂

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...