Deployment Architecture

Small Enterprise Cluster - General Questions

rewritex
Contributor

I am currently setting up a Small Enterprise Cluster ...
(1) SH (Not clustered) ( Also the License Server)
(2) indexers-(clustered)
(1) Master (Also the DMC)
(x) U-Forwarders

Apps/Field extractions - Configuration Bundle
In my research, I modify the apps as needed and drop them into the master-apps configuration bundle and push to cluster.
Q1: Do I put a mirror copy of the app onto the SH?
** Currently I am putting the APP into the SH and removing the indexes.conf so as to not override the one in the Config.Bundle.

Q2: For field extractions, do I put a duplicate copy of the APP onto the SH or do I do a combination of Config.Bundle and modified copy?

Searching from the SH
Currently when doing a search from the SH, it pulls the same data from both indexers.
Q: I only want my SH to search on the core data. Is this the correct thinking? Maybe I should modify my SF to = 1?

Multiple Admins - where will they do their work?
I have multiple admins with their own apps (ie different departments)
Q: Will each admin need to work from the master or continue to Add/Modify/Edit from the SH which will make local changes?

Sean

0 Karma
1 Solution

masonmorales
Influencer

Apps/Field extractions - Configuration Bundle
In my research, I modify the apps as needed and drop them into the master-apps configuration bundle and push to cluster.
Q1: Do I put a mirror copy of the app onto the SH?
** Currently I am putting the APP into the SH and removing the indexes.conf so as to not override the one in the Config.Bundle.
Yes, you have to put a duplicate copy of app/TA onto the SH. If the app only contains dashboards, you do not need to push it to the indexer cluster.

Q2: For field extractions, do I put a duplicate copy of the APP onto the SH or do I do a combination of Config.Bundle and modified copy?
Field extractions only live on the SH. The only things you have to push from the master to the indexer cluster are any parsing settings within props and transforms, as well as the indexes.conf.

Searching from the SH
Currently when doing a search from the SH, it pulls the same data from both indexers.
Q: I only want my SH to search on the core data. Is this the correct thinking? Maybe I should modify my SF to = 1?
Replicated data will not cause duplicates to be displayed in the search results. This sounds like a forwarder problem. How have you configured outputs.conf?

Multiple Admins - where will they do their work?
I have multiple admins with their own apps (ie different departments)
Q: Will each admin need to work from the master or continue to Add/Modify/Edit from the SH which will make local changes?
If they are doing field extractions and dashboards, they can just make those changes at the SH. Again, the only thing you need to push to the indexes is configurations related to parsing.

View solution in original post

0 Karma

masonmorales
Influencer

Apps/Field extractions - Configuration Bundle
In my research, I modify the apps as needed and drop them into the master-apps configuration bundle and push to cluster.
Q1: Do I put a mirror copy of the app onto the SH?
** Currently I am putting the APP into the SH and removing the indexes.conf so as to not override the one in the Config.Bundle.
Yes, you have to put a duplicate copy of app/TA onto the SH. If the app only contains dashboards, you do not need to push it to the indexer cluster.

Q2: For field extractions, do I put a duplicate copy of the APP onto the SH or do I do a combination of Config.Bundle and modified copy?
Field extractions only live on the SH. The only things you have to push from the master to the indexer cluster are any parsing settings within props and transforms, as well as the indexes.conf.

Searching from the SH
Currently when doing a search from the SH, it pulls the same data from both indexers.
Q: I only want my SH to search on the core data. Is this the correct thinking? Maybe I should modify my SF to = 1?
Replicated data will not cause duplicates to be displayed in the search results. This sounds like a forwarder problem. How have you configured outputs.conf?

Multiple Admins - where will they do their work?
I have multiple admins with their own apps (ie different departments)
Q: Will each admin need to work from the master or continue to Add/Modify/Edit from the SH which will make local changes?
If they are doing field extractions and dashboards, they can just make those changes at the SH. Again, the only thing you need to push to the indexes is configurations related to parsing.

0 Karma

rewritex
Contributor

Thanks for the fast response ...

The duplicates issue seems to be fixed. I think it was my inputs.conf on the forwarder

After updating my _TCP_ROUTING = entry to point to the correct groups within my outputs.conf, things are working.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...