Splunk Enterprise

Deploying deployer to two search head cluster

anglewwb35
Explorer

Hello, I am currently trying to deploy a single deployer across two different search head clusters but am having trouble finding detailed steps on how to do this. I have used the same cluster label and secret for both clusters. To differentiate the clusters, I attempted to assign different captains as follows:

For Cluster A

bootstrap shcluster-captain -servers_list "https://cluster_A_IP:8089, https://cluster_A_IP:8089, https://cluster_A_IP:8089"

For Cluster B

bootstrap shcluster-captain -servers_list "https://cluster_B_IP:8089, https://cluster_B_IP:8089, https://cluster_B_IP:8089"

I am unsure if this setup correctly separates the two clusters while using the same deployer. Could you provide guidance on whether this approach is effective or suggest an alternative method? Thank you so much

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Do you have at least 6 nodes (3+3) for those two SHCs? If yes, then you should do bootstraps 1st e.g for first three nodes and selecting one of those and captain. Then do same for last three nodes and select one of those to be a captain. There are clear instructions how to do it for one SHC in docs.splunk.com

But why you are needing two SHC with only one deployer? Have you tens of members on both SHC or what is your business reason for that configuration?

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Do you have at least 6 nodes (3+3) for those two SHCs? If yes, then you should do bootstraps 1st e.g for first three nodes and selecting one of those and captain. Then do same for last three nodes and select one of those to be a captain. There are clear instructions how to do it for one SHC in docs.splunk.com

But why you are needing two SHC with only one deployer? Have you tens of members on both SHC or what is your business reason for that configuration?

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...