Deployment Architecture

do Deployment Servers require the [clustering] stanza in their server.conf files

Gregski11
Contributor

we have an Indexer Cluster and the Indexers have a [clustering] stanza in their server.conf files, same goes for the Search Heads, however do the two Deployment servers that we have need a [clustering] stanza in their server.conf files as well?

I am new to Splunk, and I ask because I noticed one Deployment server has it while the other one does not.

 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Gregski11,

no, Deployment Server isn't a clustered role, so you don't need the [clustering] stanza in server.conf, this is a stanza only for Indexers and Search Heads, in other words for the clusterizable roles.

You can have two Deployment Servers, but you can addreass only one from each server, you cannot addreass two DSs from one server.

It isn't a Single Point of failure of your architecture because DS isn't clustarizable and your infrastructure can work also when the DS  is down.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Gregski11,

no, Deployment Server isn't a clustered role, so you don't need the [clustering] stanza in server.conf, this is a stanza only for Indexers and Search Heads, in other words for the clusterizable roles.

You can have two Deployment Servers, but you can addreass only one from each server, you cannot addreass two DSs from one server.

It isn't a Single Point of failure of your architecture because DS isn't clustarizable and your infrastructure can work also when the DS  is down.

Ciao.

Giuseppe

Gregski11
Contributor

thank you so much, makes sense, I will be removing the [clustering] stanza from the Deployment Servers that have it

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...