Deployment Architecture

Stripping down dedicated deployment server?

mfrost8
Builder

We built a dedicated deployment server a while back when we started noticing (thanks to Splunk support) that running it in the same Splunk indexer was interfering with indexing operations a little. So we now have a dedicated deployment server instance that also runs on one of the indexer hosts.

It seems as if the deployment server, while more than a fileserver, is really doing considerably less than a full Splunk server, yet that's what the basic file tree for the deployment server is. I realize there isn't a separate deployment server only package like the universal forwarder (maybe someday?), but I'm wondering if there isn't some way that one can turn off more things in the Splunk deployment server to lighten its footprint.

I realize that I can turn off splunkweb and can tune the phonehome intervals. I don't suppose that other things can be turned off in the same vein as say things that were turned off in the lightweight forwarder to make the deployment server smaller?

Thanks!

Tags (1)
1 Solution

jrodman
Splunk Employee
Splunk Employee

It's a valid idea. We haven't done all that legwork.

You could downsize the logs in log.cfg. You could play with fire in default-mode.conf but its quite easy to get into some unpleasant state that way.

If the memory use is unworkably large, maybe we should investigate. If its I/O etc, we should just turn off the inputs, or make it forward its logs elsewhere.

If its just the installed size, I doubt its worth your time.

View solution in original post

jrodman
Splunk Employee
Splunk Employee

It's a valid idea. We haven't done all that legwork.

You could downsize the logs in log.cfg. You could play with fire in default-mode.conf but its quite easy to get into some unpleasant state that way.

If the memory use is unworkably large, maybe we should investigate. If its I/O etc, we should just turn off the inputs, or make it forward its logs elsewhere.

If its just the installed size, I doubt its worth your time.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...