Hello all! I've inherited a large Splunk deployment and I've been given some leniency with setting up, or rather, revamping the monitoring. Environment: - 3 Primary locations - 30 - 40 Indexers per location - 10 - 12 Search Heads per location - 1 DMC per location ** The numbers above don't account for BCP or lower environments. Right now each DMC is responsible for its location, however there is a push to have the entire deployment's "health" available in a "single pane of glass". Without regard to cost, what is the ideal method to accomplish this? I've toyed with standing up a single DMC at one of the regions and plugging all indexers, SH, etc. into it simply for the health perspective. The same scenario as I just mentioned but in Splunk Cloud is also possible. Also using one of the existing DMC's as the master for all regions is on the table. I'd love to hear what is currently out there, or what architecture makes the most sense in this scenario. Cheers!
... View more