Deployment Architecture

how to configure Splunk search head cluster behind an F5 load balancer ?

Path Finder

We don’t have anything set up currently for load balancing and this is something we are planning for first time using new version (6.2) of splunk. The load balancer set up I am looking for is F5 residing between the users and the cluster members (search heads).

Can anyone provide the process or documentation for setting this up ?

Labels (1)
0 Karma
1 Solution

Path Finder

Hello,

We just built a new SH Cluster and put ours behind an F5.
Nothing too complicated to setup. You will need a VIP associated to URL that users can get to, ex: Splunk.Company.com

Have that forward to your Search Peers IP's
10.x.x.x, 10.x.x.x, 10.x.x.x

If you use the default ports (8000 for web), make sure you change the port forwarding.

Last, enable sticky sessions.

If you find that every time you login, it seems to reset and make you log in again, you probably are missing the sticky sessions.

Thanks,
James

View solution in original post

0 Karma

Path Finder

Hello,

We just built a new SH Cluster and put ours behind an F5.
Nothing too complicated to setup. You will need a VIP associated to URL that users can get to, ex: Splunk.Company.com

Have that forward to your Search Peers IP's
10.x.x.x, 10.x.x.x, 10.x.x.x

If you use the default ports (8000 for web), make sure you change the port forwarding.

Last, enable sticky sessions.

If you find that every time you login, it seems to reset and make you log in again, you probably are missing the sticky sessions.

Thanks,
James

View solution in original post

0 Karma

New Member

What do you mean by 'stick session'?

0 Karma

Builder

Hi @jmheaton, did you also make your Search Heads HTTPS based? If yes, please share the method you used to configure that. Thanks.

0 Karma

Path Finder

We set it up but I am getting an xml page when i browse using just the VIP. The VIP will listen for https requests on 443 and forward to the real servers on 4301.

Can you please suggest ?

Appreciate your help on this!

0 Karma

Path Finder

Thanks for your response! I am confused with the statement "Have that forward to your Search Peers IP's".

You mean forward to our search head IP's ?

Thanks,
Sam

0 Karma

Path Finder

Yeah, i have been working on an index cluster project and wrote peers instead of heads 🙂

0 Karma

Path Finder

no problem. Appreciate your response.

Thanks,
Sam

0 Karma

SplunkTrust
SplunkTrust