Splunk Enterprise

Deploying deployer to two search head cluster

anglewwb35
Explorer

Hello, I am currently trying to deploy a single deployer across two different search head clusters but am having trouble finding detailed steps on how to do this. I have used the same cluster label and secret for both clusters. To differentiate the clusters, I attempted to assign different captains as follows:

For Cluster A

bootstrap shcluster-captain -servers_list "https://cluster_A_IP:8089, https://cluster_A_IP:8089, https://cluster_A_IP:8089"

For Cluster B

bootstrap shcluster-captain -servers_list "https://cluster_B_IP:8089, https://cluster_B_IP:8089, https://cluster_B_IP:8089"

I am unsure if this setup correctly separates the two clusters while using the same deployer. Could you provide guidance on whether this approach is effective or suggest an alternative method? Thank you so much

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Do you have at least 6 nodes (3+3) for those two SHCs? If yes, then you should do bootstraps 1st e.g for first three nodes and selecting one of those and captain. Then do same for last three nodes and select one of those to be a captain. There are clear instructions how to do it for one SHC in docs.splunk.com

But why you are needing two SHC with only one deployer? Have you tens of members on both SHC or what is your business reason for that configuration?

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Do you have at least 6 nodes (3+3) for those two SHCs? If yes, then you should do bootstraps 1st e.g for first three nodes and selecting one of those and captain. Then do same for last three nodes and select one of those to be a captain. There are clear instructions how to do it for one SHC in docs.splunk.com

But why you are needing two SHC with only one deployer? Have you tens of members on both SHC or what is your business reason for that configuration?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...