Deployment Architecture

How to configure search head clustering in multisite environment

Sourabhv05
Communicator

I had setup multisite cluster 6.2.1. Details of my Splunk environment are mentioned below

We have two sites
MasterNode : 1
Search Head : 2 search head in site 1 and 1 search head in site 2 .
Peers : 3 Peers at site 1 and 1 peers at site 2.

I am looking to setup search head clustering. Can i setup 1 search head cluster and include all search heads ( 2 from site 1 and 1 from site 2) or i had to setup two diffrent search head clusters ?

Please let me know the configurations to perfom the search head clustering based on above details.

regards,
Sourabh Varshney

Lowell
Super Champion

The docs say:

 Running a cluster across multiple sites is not currently supported. Search head clusters have been tested only with all members running on a single site.

Steve_G_
Splunk Employee
Splunk Employee

That restriction was removed with release 6.3. For current guidelines, see http://docs.splunk.com/Documentation/Splunk/6.5.2/DistSearch/SHCsystemrequirements#Search_head_clust...

0 Karma

mikaelbje
Motivator

Hmm, not supported/tested is one thing, but I'm curious whether it would work. I'll open a support case to get some more info. Thanks for the clarification.

0 Karma

Sourabhv05
Communicator

I have configured Search Head Clustering on Windows Servers and it is working fine with some limitations.

antonyhan
Path Finder

what limitations did you have please?
thanks.

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

Yes, You can set up a single SHC with nodes from 2 different sites. But keep in mind that if Site 1 is lost, then Site 2 won't be able to run any of your scheduled searches (you can still run your adhoc searches). This is due to majority node requirement in SHC.

Refer here

http://docs.splunk.com/Documentation/Splunk/6.2.1/DistSearch/Runtimeissues#Site_failure_can_prevent_...

http://docs.splunk.com/Documentation/Splunk/6.2.1/DistSearch/SHCarchitecture#Captain_election_proces...

Sourabhv05
Communicator

I am able to run the initialize command but while creating a captian by running bootstarp command

splunk bootstrap shcluster-captain -servers_list ":,:,..."

I am getting error as splunk does not recognize bootstarp. Please check command or take help.

0 Karma
Get Updates on the Splunk Community!

Avoid Certificate Expiry Issues in Splunk Enterprise with Certificate Assist

This blog post is part 2 of 4 of a series on Splunk Assist. Click the links below to see the other ...

Using Machine Learning for Hunting Security Threats

REGISTER NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more ...

Security Highlights | November 2022 Newsletter

 November 2022 2022 Gartner Magic Quadrant for SIEM: Splunk Named a Leader for the 9th Year in a RowSplunk is ...