Deployment Architecture

Splunk server roles

splunkreal
Motivator

Hello,

could you explain me in details the possible roles of cluster member below and what would you advice for :

2 search heads
2 indexers
1 management console (cluster master at least, deployment server & SHC deployer?)

alt text

Thanks a lot.

* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi realsplunk,
I suggest to read http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Basicclusterarchitecture and http://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/SHCarchitecture

Anyway in Search Head cluster you have:

  • Search Head Captain
  • Search Heads
  • Deployer: manage replication between SHs

Note that in Search Head Cluster you must have at least 3 SHs.

In Indexer Cluster you have

  • Search Peers (at least 2)
  • Master Node

Deployment Server must be a dedicated server if you have to manage more than 50 Forwarders

Bye.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi realsplunk,
I suggest to read http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Basicclusterarchitecture and http://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/SHCarchitecture

Anyway in Search Head cluster you have:

  • Search Head Captain
  • Search Heads
  • Deployer: manage replication between SHs

Note that in Search Head Cluster you must have at least 3 SHs.

In Indexer Cluster you have

  • Search Peers (at least 2)
  • Master Node

Deployment Server must be a dedicated server if you have to manage more than 50 Forwarders

Bye.
Giuseppe

splunkreal
Motivator

Thanks cusello, however why 3 SHs are required? Is there any doc on this requirement?

* If this helps, please upvote or accept solution if it solved *
0 Karma

gcusello
SplunkTrust
SplunkTrust
0 Karma

splunkreal
Motivator

Thank Giuseppe, we use virtual machines FYI but yes I just read 3 SHs are better in case one search head fails.

* If this helps, please upvote or accept solution if it solved *
0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...