Splunk Enterprise

Deploying deployer to two search head cluster

anglewwb35
Explorer

Hello, I am currently trying to deploy a single deployer across two different search head clusters but am having trouble finding detailed steps on how to do this. I have used the same cluster label and secret for both clusters. To differentiate the clusters, I attempted to assign different captains as follows:

For Cluster A

bootstrap shcluster-captain -servers_list "https://cluster_A_IP:8089, https://cluster_A_IP:8089, https://cluster_A_IP:8089"

For Cluster B

bootstrap shcluster-captain -servers_list "https://cluster_B_IP:8089, https://cluster_B_IP:8089, https://cluster_B_IP:8089"

I am unsure if this setup correctly separates the two clusters while using the same deployer. Could you provide guidance on whether this approach is effective or suggest an alternative method? Thank you so much

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Do you have at least 6 nodes (3+3) for those two SHCs? If yes, then you should do bootstraps 1st e.g for first three nodes and selecting one of those and captain. Then do same for last three nodes and select one of those to be a captain. There are clear instructions how to do it for one SHC in docs.splunk.com

But why you are needing two SHC with only one deployer? Have you tens of members on both SHC or what is your business reason for that configuration?

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Do you have at least 6 nodes (3+3) for those two SHCs? If yes, then you should do bootstraps 1st e.g for first three nodes and selecting one of those and captain. Then do same for last three nodes and select one of those to be a captain. There are clear instructions how to do it for one SHC in docs.splunk.com

But why you are needing two SHC with only one deployer? Have you tens of members on both SHC or what is your business reason for that configuration?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...