Getting Data In

Is it possible for the cluster master to have a different OS than the indexer cluster peers? What are the potential drawbacks?

Julieda
Explorer

My Splunk environment has two indexers running on VMs with Linux OS, and I want to create an indexer cluster. My third VM is a Windows machine, and I want to use this VM as a cluster master for the indexer cluster. I have read the documentation (http://docs.splunk.com/Documentation/Splunk/6.0/Indexer/Systemrequirements), and I am aware that all nodes should run the same OS, but is it possible to have a cluster master running a different OS than the indexer cluster itself? If yes, what are the potential drawbacks?

Any help would be appreciated.

0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

Please re-read this, which states that:

For example, to deploy a cluster consisting of three peers, one master, and one search head, you need five Splunk Enterprise instances running on five machines connected by a high-speed network. All instances must be at the same Splunk Enterprise version level (for example, 5.0.3). And all machines must be running the same operating system.

So yes, the cluster master is included in this requirement. Why would you chose a different OS?
The likely drawback is that you are running an unsupported configuration if chose to deploy differently.
Hope this helps!

View solution in original post

s2_splunk
Splunk Employee
Splunk Employee

Please re-read this, which states that:

For example, to deploy a cluster consisting of three peers, one master, and one search head, you need five Splunk Enterprise instances running on five machines connected by a high-speed network. All instances must be at the same Splunk Enterprise version level (for example, 5.0.3). And all machines must be running the same operating system.

So yes, the cluster master is included in this requirement. Why would you chose a different OS?
The likely drawback is that you are running an unsupported configuration if chose to deploy differently.
Hope this helps!

Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...