Deployment Architecture

create/add splunk search head cluster to existing index cluster (with working search heads)

bryanwiggins
Path Finder

[env]
centos 7, splunk enterprise 6.4.1
4x search heads (-mode searchhead -master_uri cluster_master) [2 heads are set to be decommissioned]
3x clustered index peers (cluster master) <- multi site capable, 1 site live for now
2x heavy forwarders
load balanced reverse proxy serving search head pool url access for users

question:
i am in the process of researching implementing a search head cluster in the current model (see [env] above) and have been looking at the following documentation; http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCdeploymentoverview

1: am i able to use 3 search head nodes that are already pointing the the back-end index cluster and then just run the commands to add these members to the search head cluster (and elect a captain) <- also add the deployer role to the index cluster master?

2: if no to No.1 do I create 3x new nodes as search heads, then create the search head cluster and a separate deployer node - if so, how best do i point these to use the index cluster peers?

I'm going to running this up in a lab, so I will update progress but if anyone has any initial guidance/pointers, that would be very much appreciated.

Thx
Bry

Tags (1)
0 Karma
1 Solution

bryanwiggins
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

followed the guide above and results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

View solution in original post

bryanwiggins
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

followed the guide above and results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

bryanwiggins
Path Finder

also saw this link in the document about integrating shc with an idxc; http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

0 Karma

bryanwiggins
Path Finder

looking more like i create the shc then add to the idx cluster.

0 Karma

bryanwiggins
Path Finder

i have a multi-node splunk lab setup now (to emulate my ^^^[env]). i will post my findings here once i have fully tested the options.

0 Karma

bryanwiggins
Path Finder

ok, results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...