Deployment Architecture

Splunk server roles

splunkreal
Motivator

Hello,

could you explain me in details the possible roles of cluster member below and what would you advice for :

2 search heads
2 indexers
1 management console (cluster master at least, deployment server & SHC deployer?)

alt text

Thanks a lot.

* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi realsplunk,
I suggest to read http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Basicclusterarchitecture and http://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/SHCarchitecture

Anyway in Search Head cluster you have:

  • Search Head Captain
  • Search Heads
  • Deployer: manage replication between SHs

Note that in Search Head Cluster you must have at least 3 SHs.

In Indexer Cluster you have

  • Search Peers (at least 2)
  • Master Node

Deployment Server must be a dedicated server if you have to manage more than 50 Forwarders

Bye.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi realsplunk,
I suggest to read http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Basicclusterarchitecture and http://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/SHCarchitecture

Anyway in Search Head cluster you have:

  • Search Head Captain
  • Search Heads
  • Deployer: manage replication between SHs

Note that in Search Head Cluster you must have at least 3 SHs.

In Indexer Cluster you have

  • Search Peers (at least 2)
  • Master Node

Deployment Server must be a dedicated server if you have to manage more than 50 Forwarders

Bye.
Giuseppe

splunkreal
Motivator

Thanks cusello, however why 3 SHs are required? Is there any doc on this requirement?

* If this helps, please upvote or accept solution if it solved *
0 Karma

gcusello
SplunkTrust
SplunkTrust
0 Karma

splunkreal
Motivator

Thank Giuseppe, we use virtual machines FYI but yes I just read 3 SHs are better in case one search head fails.

* If this helps, please upvote or accept solution if it solved *
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...