Dear Sir/Madam,
With someone retiring, I can advance from being a Splunk Enterprise Certified Administrator to becoming a Splunk Architect. To gain experience and practice, I would like to set up a home lab to take the Splunk Architect courses.
I want to set up a virtual Home Lab with a Splunk distributed search environment, an indexer cluster, and a deployment server to deploy all the apps to the forwarders. Should I spin up how many Ubuntu Server VMs in Hyper-V? One search head, two indexers (right? ), a deployment server, a management node, and an HF for practice. Six VMs in total? Is that too few? or too many? Depending on how many Splunk roles each VM can play, I'm still determining. Online, this information is hard to find.
I'm only going to ingest a few data sources for practice.
Hi @informations4,
in my opinion, in general, you should have:
I configured my lab with six VMs and I used my laptop as client to manage using the DS.
Ciao.
Giuseppe