Sorry for too many questions
This is our environment
6 Splunk servers
1) splunk01 – Ad HOC Search head used for standalone searches
47.14 GB Physical Memory, 10 CPU Cores
2) splunk02 – Enterprise Security Search Head has Enterprise Security app installed on it.
125.75 GB Physical Memory, 24 CPU Cores
3) splunk03 – Indexer – Syslog plus Indexer server
62.75 GB Physical Memory, 24 CPU Cores
4) splunk04 – Indexer – Syslog plus Indexer server
62.75 GB Physical Memory, 24 CPU Cores
Below two Splunk servers are on a host that has several other VMs hosted on it.
5) splunk05 – License Master plus Indexer cluster master
7.64 GB Physical Memory, 4 CPU Cores
6) splunk06 – Deployment Server
3.7 GB Physical Memory, 2 CPU Cores
Question 1) Our indexers 3&4 are also Syslog servers with HD of 5tb each is it a best practice to have Indexers and Syslog servers on the same box?
Question 2) Our License master with its current RAM and CPU config as stated above is it enough to be a License master?
Question 3) Since our Syslog and indexer reside on the same box does that mean our HFs don't play any role in forwarding data?
Question 4) Can we install DMC on our license master?
... View more