Deployment Architecture

create/add splunk search head cluster to existing index cluster (with working search heads)

bryanwiggins
Path Finder

[env]
centos 7, splunk enterprise 6.4.1
4x search heads (-mode searchhead -master_uri cluster_master) [2 heads are set to be decommissioned]
3x clustered index peers (cluster master) <- multi site capable, 1 site live for now
2x heavy forwarders
load balanced reverse proxy serving search head pool url access for users

question:
i am in the process of researching implementing a search head cluster in the current model (see [env] above) and have been looking at the following documentation; http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCdeploymentoverview

1: am i able to use 3 search head nodes that are already pointing the the back-end index cluster and then just run the commands to add these members to the search head cluster (and elect a captain) <- also add the deployer role to the index cluster master?

2: if no to No.1 do I create 3x new nodes as search heads, then create the search head cluster and a separate deployer node - if so, how best do i point these to use the index cluster peers?

I'm going to running this up in a lab, so I will update progress but if anyone has any initial guidance/pointers, that would be very much appreciated.

Thx
Bry

Tags (1)
0 Karma
1 Solution

bryanwiggins
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

followed the guide above and results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

View solution in original post

bryanwiggins
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

followed the guide above and results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

bryanwiggins
Path Finder

also saw this link in the document about integrating shc with an idxc; http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

0 Karma

bryanwiggins
Path Finder

looking more like i create the shc then add to the idx cluster.

0 Karma

bryanwiggins
Path Finder

i have a multi-node splunk lab setup now (to emulate my ^^^[env]). i will post my findings here once i have fully tested the options.

0 Karma

bryanwiggins
Path Finder

ok, results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...