Knowledge Management

Need some understanding of Splunk server roles?

mgiddens
Path Finder

I'm rearranging my Splunk server roles, and I noticed that if I remove SH role from my indexer, I still get the options to configure search peers? I seem to misunderstand what the server roles really do the for the Splunk instance because I imagined that only a server configured as a search head would have this option available? Can someone please explain exactly what the server roles both do for a Splunk server and what functionality it takes away from a server not having a role if any?

Tags (1)
0 Karma
1 Solution

ragedsparrow
Contributor

The Server roles are typically central around your function as well as populating the monitoring console dashboards. Enterprise Splunk has the ability to function as any of these roles. If you take the server role off of one of the servers, that typically is only used for ensuring that the monitoring console places/removes that server from the relevant dashboard. You still have the ability to utilize all of the functions that Splunk Enterprise has to offer, you just typically don't utilize functions that you don't need for that server's role (i.e. Having search peers on indexers).

Does that clear anything up?

View solution in original post

0 Karma

ragedsparrow
Contributor

The Server roles are typically central around your function as well as populating the monitoring console dashboards. Enterprise Splunk has the ability to function as any of these roles. If you take the server role off of one of the servers, that typically is only used for ensuring that the monitoring console places/removes that server from the relevant dashboard. You still have the ability to utilize all of the functions that Splunk Enterprise has to offer, you just typically don't utilize functions that you don't need for that server's role (i.e. Having search peers on indexers).

Does that clear anything up?

0 Karma

mgiddens
Path Finder

This is exactly what I needed. Thanks for the timely response and yes that clears it up quite nicely! Makes alot more sense now based on what I was seeing.

Regards

mgiddens

0 Karma

ragedsparrow
Contributor

Awesome! Glad I could help!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...