Splunk Enterprise Security

Splunk Enterprise Distributed Deployment Guide RHEL 7

grantk87
New Member

Hello,

I have inherited a Splunk Enterprise deployment with a mixed OS (Windows/Linux) environment. We are in the process of converting this to a full linux instance and want to leave the Hybrid instance behind. Could someone provide me a link to a step-by-step configuration process for setting up the following:

  1. A Search Head Cluster (3 search heads)

  2. Indexer Cluster (5 indexers). - NOTE: This is already functioning in the old instance, so I believe I can figure this one out. However, I just want to ensure this is done right.

  3. Deployer/Cluster Master

We already have a Deployment server in place and 4 Heavy forwarders. My biggest concern is setting up the search head cluster since we do not currently have this implemented. Any help will be greatly appreciated.

Thanks
grantk1987

0 Karma

inventsekar
SplunkTrust
SplunkTrust

this is a big task.. maybe, you need to this step by step.. and when you are stuck at a particular step, you can ask that issue, so that we can reply..

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

codebuilder
Influencer

https://docs.splunk.com/Documentation/Splunk/7.3.0/DistSearch/SHCdeploymentoverview

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...