Deployment Architecture

Tear down entire cluster (search head and indexer) every week

hcheang
Path Finder

Hello,

I have a customer who wants to tear down the entire cluster every week.
Long story short, they do not want long lasting VMs.

Does anyone know where I can find some reference document or quotes from Splunk this is recommended?

I have done this from time to time when there were specific reasons (OS out of support, going AWS or Azure)
but not as a regular maintenance work.

Is anyone else doing this?

0 Karma
1 Solution

amitm05
Builder

I am not sure if you'd find many people who might be using Splunk in this manner.
But however at a high level for your requirement, it looks like you'll have to create templates for your VMs with specific Splunk Roles i.e indexers, search heads, Cluster Master, License Master etc.

If its only the clusters that you'd require to tear down and not the forwarders layer. You'd want to also reserve IPs for your indexers. So that whenever your clusters are available, forwarders can start sending data.

You'd require to consider connectivity tests to be run everytime after bringing up the clusters back. As well as a devops pipeline for installing the Splunk and deploying the relevant splunk confs.

An automated LDAP integration of your SHs so that your users are able to access and not have to do it all over manually.

I hope this gives you some tips.

View solution in original post

amitm05
Builder

I am not sure if you'd find many people who might be using Splunk in this manner.
But however at a high level for your requirement, it looks like you'll have to create templates for your VMs with specific Splunk Roles i.e indexers, search heads, Cluster Master, License Master etc.

If its only the clusters that you'd require to tear down and not the forwarders layer. You'd want to also reserve IPs for your indexers. So that whenever your clusters are available, forwarders can start sending data.

You'd require to consider connectivity tests to be run everytime after bringing up the clusters back. As well as a devops pipeline for installing the Splunk and deploying the relevant splunk confs.

An automated LDAP integration of your SHs so that your users are able to access and not have to do it all over manually.

I hope this gives you some tips.

amitm05
Builder

Please let us know if this helps or if you require to discuss anymore. Thanks

0 Karma

skalliger
Motivator

The first question you have to ask is: why? What's the reason for doing that? You'll need to do quite some automation work.

Skalli

0 Karma

adonio
Ultra Champion

go containers then ...

0 Karma

hcheang
Path Finder

you mean the docker?

0 Karma

adonio
Ultra Champion

yes ... or other container / serverless technology ...
overall, i think what your client wants is a terrible idea, but maybe i am missing the use case or reason behind it.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...