Splunk Search

Architecture

revanthammineni
Path Finder

Can Deployer and Deployment server be on a Single instance? What are Management servers in Splunk?

Tags (1)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

My response is based on the assumption that you mean can these be deployed on their own dedicated standalone instances as a single role as described.

Yes, the deployer (for SHC) and the Deployment Server can be on a dedicated instance. This can be a virtual instance, as the system requirements are pretty low. Please follow and maintain the minimum system requirements as noted at Splunk Docs.

Yes, the Deployment Server (DS) can be deployed on a dedicated instance. Per our best practices, we recommend that any DS that servers more then 50 clients should be on a dedicated instance.

0 Karma

revanthammineni
Path Finder

Hey! Thanks for responding. Sorry for not being clear with my question. What I meant was, If we can deploy both deployer and the deployment server on a single instance?

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi revanthammineni,

Here is some helpful inside about what are the management components in Splunk : https://docs.splunk.com/Documentation/Splunk/latest/Deploy/Manageyourdeployment#Types_of_management_...

You might notice in the table that it is possible to have the DS and the Deployer component on one server BUT as @esix_splunk correctly mentioned it is not recommended and it is also stated in the docs just above the table:

In some low-use situations, you might
be able to combine more than two
management components on a single
instance, although it is not generally
recommended that you do so. If you
intend to do so, monitor the
performance impacts closely to ensure
that you are not overloading the
instance.

Hope this helps ...

cheers, MuS

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...