Splunk Enterprise

How to configure Splunk as different Instance like Indexers and Search Head etc

Ashwini008
Communicator

Hi,

I am setting up Splunk Arcitecture.To start, After installing the tar file how do we configure that tar to act as Heavy Forwader?

what is the configuration file which make it as HF?

Any suggestion or doc please?

 

Tags (1)
0 Karma

michael_wong
Path Finder

Heavy Forwareder, Search Head,Indexer,license Master, Deployment server, these are different role for splunk, the installation is no different among them. The only difference is how you do the configuration. You can use one instance to play all the role in one server., OR deploy each role in different servers, that depend on the scaling of your deployment.

https://docs.splunk.com/Documentation/Splunk/8.1.3/Deploy/Distributedoverview

0 Karma

Ashwini008
Communicator

What configuration gets created when we run the below command?

splunk enable app SplunkForwarder -auth <username>:<password>

0 Karma

aasabatini
Builder

Hi @Ashwini008 

this comand is for the uf.

Please read this documentation to understand the difference from UF to HF.

https://www.splunk.com/en_us/blog/tips-and-tricks/universal-or-heavy-that-is-the-question.html

 

Karma given or solution confirmation is appreciated

 

 

aasabatini
Builder

Hi @Ashwini008 ,

the installation of splunk ROLE  is the same, for the HF you need to set up the forwarder license.

 

Please check the documentation for the roles

https://docs.splunk.com/Documentation/Splunk/8.1.3/Updating/Deploymentserverarchitecture

Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.