Other Usage

Setting up a home lab

yemerchandise
Engager

A question about the architecture of the HomeLab
Hello,
I am a Splunk Enterprise Certified Admin who has an opportunity to advance to Splunk Architect with someone retiring. I plan on taking the Splunk Architect courses but would like to set up a home lab to give myself practice and experience.

To best prepare me, I’d like to set up a virtual Home Lab with a Splunk distributed search environment, an indexer cluster, and a deployment server to deploy all the apps to the forwarders. How many total Ubuntu Server VMs in Hyper-V should I spin up? I think one search head, at least two indexers (right?), the deployment server, a management node, and possibly an HF for practice. So maybe a total of six VMs? Or is that too few….or too many? It depends on how many Splunk roles each VM can play, which I’m not entirely sure about. It isn’t easy to find this information online.

I’m not planning on ingesting much data, just a few data sources for practice. This is more of a Proof of Concept and learning opportunity for me from an architectural perspective.

Labels (1)

richgalloway
SplunkTrust
SplunkTrust

Have a look at the description for the Deployment lab at https://education.splunk.com/instructor-led-training/splunk-enterprise-deployment-practical-lab.  This part of the Architect certification process worries applicants the most so you may want to practice the tasks outlined.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...