Other Admin

Clustered environment Search Head/Indexers

YJ
Explorer

My current Splunk infra setup is clustered for Search Heads and Indexers. and  we are using deployer and cluster master to manage configs for the respective SH and IDX. For example, can I manually placed an updated config in SH1 and then run a rolling restart so they will sync/replicate with each other. ? This is in the event the Deployer is down. But eventually once the Deployer is up , we will place the updated config in Deployer. So that when we run a sync, it will not affect/remove the file from the SH cluster. Will there be any issues in this scenario?

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

No. The SHC will not replicate files you manually place on one of the members of the cluster. That's what the deployer is for.

You could manually place some content on each of the SHs in cluster and that could work for some time (well, that's why you don't distribute/overwrite built-in apps from the deployer so you don't cause conflicts in case of upgrade).

Also when the deployer is up you have to manually push the configs, it will not happen automatically.

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

No. The SHC will not replicate files you manually place on one of the members of the cluster. That's what the deployer is for.

You could manually place some content on each of the SHs in cluster and that could work for some time (well, that's why you don't distribute/overwrite built-in apps from the deployer so you don't cause conflicts in case of upgrade).

Also when the deployer is up you have to manually push the configs, it will not happen automatically.

Get Updates on the Splunk Community!

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...

New This Month in Splunk Observability Cloud - Synthetic Monitoring updates, UI ...

This month, we’re delivering several platform, infrastructure, application and digital experience monitoring ...