Deployment Architecture

create/add splunk search head cluster to existing index cluster (with working search heads)

bryanwiggins
Path Finder

[env]
centos 7, splunk enterprise 6.4.1
4x search heads (-mode searchhead -master_uri cluster_master) [2 heads are set to be decommissioned]
3x clustered index peers (cluster master) <- multi site capable, 1 site live for now
2x heavy forwarders
load balanced reverse proxy serving search head pool url access for users

question:
i am in the process of researching implementing a search head cluster in the current model (see [env] above) and have been looking at the following documentation; http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCdeploymentoverview

1: am i able to use 3 search head nodes that are already pointing the the back-end index cluster and then just run the commands to add these members to the search head cluster (and elect a captain) <- also add the deployer role to the index cluster master?

2: if no to No.1 do I create 3x new nodes as search heads, then create the search head cluster and a separate deployer node - if so, how best do i point these to use the index cluster peers?

I'm going to running this up in a lab, so I will update progress but if anyone has any initial guidance/pointers, that would be very much appreciated.

Thx
Bry

Tags (1)
0 Karma
1 Solution

bryanwiggins
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

followed the guide above and results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

View solution in original post

bryanwiggins
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

followed the guide above and results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

bryanwiggins
Path Finder

also saw this link in the document about integrating shc with an idxc; http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

0 Karma

bryanwiggins
Path Finder

looking more like i create the shc then add to the idx cluster.

0 Karma

bryanwiggins
Path Finder

i have a multi-node splunk lab setup now (to emulate my ^^^[env]). i will post my findings here once i have fully tested the options.

0 Karma

bryanwiggins
Path Finder

ok, results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...