Deployment Architecture

Warning at MC : "At least one of your instances is a deployment server plus other non-deployer roles"

saurabh_tek11
Communicator

Splunk MC while setting up in distributed mode has error : "At least one of your instances is a deployment server plus other non-deployer roles. We recommend only deployer roles per deployment server."

I have edited the role and kept - DS, KV store and LM together.

Basically in my infra, i have DS, LM and MC all on one box.

Why this warning is coming, i am not able to understand what this want to say and What shall i do to not get this warning?

0 Karma

gjanders
SplunkTrust
SplunkTrust

The monitoring console is advising you of best practice from Plan a deployment

Because of high CPU and memory usage
during app downloads, it is
recommended that the deployment server
instance reside on a dedicated
machine.

While you do not have to do this, it is recommended as when the deployment server becomes overloaded it doesn't respond to other requests for a short period of time.
If your using "MC" as cluster master, I'd suggest you do not share the roles on the same server...

0 Karma

hortonew
Builder

I wouldn't think your DS/LM would have KV store listed as a role as that's typically reserved for your search head/search cluster nodes, however that won't affect much. Even removing that, because you're configuring it as a license master it'll throw this warning. It's only a warning and doesn't affect anything. Splunk is just providing guidance that you typically want to designate single roles to your servers. These classifications are only used on the MC dashboards to filter what shows up where. You can safely ignore the message if your server is in fact configured for all those roles.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...