Deployment Architecture

best use of "spare" servers

a212830
Champion

Hi,

We upgraded to Splunk 6.1 this spring, and with that purchased new physical servers. The SH's (two) are 64 cores and 128gb of memory and the indexers are all 48 cores and 128gb of memory. I have two additional servers - one of the original servers (16 cores and 48gb of memory) and another new one that is 32 cores and 128gb of memory. I want to put these to use before I'm told to return them. However, since they don't match the specs of either of the existing SH's or indexers, I've been told (unofficially) that it's not a great idea - the servers should all be the same specs within function. Do people agree with this? Is there any reason that I couldn't make both of these either indexers or SH's? (I do plan on upgrading to 6.2 early next year).

0 Karma

ekost
Splunk Employee
Splunk Employee

Sweet. Run D.M.C. after upgrading to 6.2. And I'm sure you'll want a deployer node for the search head cluster.

martin_mueller
SplunkTrust
SplunkTrust

More uses would be as a master in an indexer cluster, as a heavy forwarder for "special needs" sources such as DBConnect, a testbed for crazy new ideas, ...

I doubt you'll need a deployer though, because running a search head cluster with just two SHs shouldn't really work... however, you could use one of the spare boxes as a dedicated captain captain_is_adhoc_searchhead = true and turn your two SHs into a working search head cluster 😄

a212830
Champion

Ideally, I'd like to add it to the SHC. Sounds like I could use it as the captain, and still have it perform searches? I'd like to take advantage of the number of cores and memory available on the 32 core server especially. For the other uses, I'm able to spin up smaller servers quickly.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...