Knowledge Management

Need some understanding of Splunk server roles?

mgiddens
Path Finder

I'm rearranging my Splunk server roles, and I noticed that if I remove SH role from my indexer, I still get the options to configure search peers? I seem to misunderstand what the server roles really do the for the Splunk instance because I imagined that only a server configured as a search head would have this option available? Can someone please explain exactly what the server roles both do for a Splunk server and what functionality it takes away from a server not having a role if any?

Tags (1)
0 Karma
1 Solution

ragedsparrow
Contributor

The Server roles are typically central around your function as well as populating the monitoring console dashboards. Enterprise Splunk has the ability to function as any of these roles. If you take the server role off of one of the servers, that typically is only used for ensuring that the monitoring console places/removes that server from the relevant dashboard. You still have the ability to utilize all of the functions that Splunk Enterprise has to offer, you just typically don't utilize functions that you don't need for that server's role (i.e. Having search peers on indexers).

Does that clear anything up?

View solution in original post

0 Karma

ragedsparrow
Contributor

The Server roles are typically central around your function as well as populating the monitoring console dashboards. Enterprise Splunk has the ability to function as any of these roles. If you take the server role off of one of the servers, that typically is only used for ensuring that the monitoring console places/removes that server from the relevant dashboard. You still have the ability to utilize all of the functions that Splunk Enterprise has to offer, you just typically don't utilize functions that you don't need for that server's role (i.e. Having search peers on indexers).

Does that clear anything up?

0 Karma

mgiddens
Path Finder

This is exactly what I needed. Thanks for the timely response and yes that clears it up quite nicely! Makes alot more sense now based on what I was seeing.

Regards

mgiddens

0 Karma

ragedsparrow
Contributor

Awesome! Glad I could help!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...