Deployment Architecture

Splunk server roles

splunkreal
Motivator

Hello,

could you explain me in details the possible roles of cluster member below and what would you advice for :

2 search heads
2 indexers
1 management console (cluster master at least, deployment server & SHC deployer?)

alt text

Thanks a lot.

* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi realsplunk,
I suggest to read http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Basicclusterarchitecture and http://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/SHCarchitecture

Anyway in Search Head cluster you have:

  • Search Head Captain
  • Search Heads
  • Deployer: manage replication between SHs

Note that in Search Head Cluster you must have at least 3 SHs.

In Indexer Cluster you have

  • Search Peers (at least 2)
  • Master Node

Deployment Server must be a dedicated server if you have to manage more than 50 Forwarders

Bye.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi realsplunk,
I suggest to read http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Basicclusterarchitecture and http://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/SHCarchitecture

Anyway in Search Head cluster you have:

  • Search Head Captain
  • Search Heads
  • Deployer: manage replication between SHs

Note that in Search Head Cluster you must have at least 3 SHs.

In Indexer Cluster you have

  • Search Peers (at least 2)
  • Master Node

Deployment Server must be a dedicated server if you have to manage more than 50 Forwarders

Bye.
Giuseppe

splunkreal
Motivator

Thanks cusello, however why 3 SHs are required? Is there any doc on this requirement?

* If this helps, please upvote or accept solution if it solved *
0 Karma

gcusello
SplunkTrust
SplunkTrust
0 Karma

splunkreal
Motivator

Thank Giuseppe, we use virtual machines FYI but yes I just read 3 SHs are better in case one search head fails.

* If this helps, please upvote or accept solution if it solved *
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...