Deployment Architecture

How to upgrade a single Search Head to a Search Head Cluster?

lucacaldiero
Path Finder

Hello,

please I would like to know if the best approach to "move" a single Search Head  to a Search Head Cluster is to deploy first a deployer, than a single-member search head cluster (connected to the deployer and elected as captain), with replication factor to 1, and then add other members to the Search Head Cluster.

 

Info here: Deploy a single-member search head cluster - Splunk Documentation

 

Thanks and kind regards.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust
0 Karma

lucacaldiero
Path Finder

Ciao Giuseppe,

thanks for helping, but I have to apologize, because my question was not well explained.

I have an environment with only one search head and I would like to move to a cluster environment; there are not other search heads at the moment.

I know that at the end I should have 1 deployer and 3 search heads, but, as told above, for the time being I have only one server: a search head.


Thanks again.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @lucacaldiero,

in this case you have to create you Cluster from zero:

  • install Deployer and the other Search Heads,
  • copy the installed apps (custom or from Splunkbase) from the actual SH to the Deployer (to the $SPLUNK_HOME/etc/shcluster folder),
  • configure the Cluster following the instructions of the previous message ,
  • deploy Apps from Deployer to all the SHs.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...