Deployment Architecture

Splunk Architecture Guidance on colocation best practices for the Search Head Cluster Deployer.



While this helpful Splunk document ( ) provides some insight on which Splunk components a Deployer can be colocated with, I'm looking for advice for my specific situation, where we are anticipating ingestion of less than 200 GB/day .

We are planning to have 2 standalone Enterprise Security Search Heads and 3 Enterprise Search Heads in a cluster. Each SH will run on instances with 16CPU and 64GB RAM. We are planning to colocate the Cluster Master and License Master (8 CPU, 64GB RAM), as well as Deployment Server with the Monitoring Console (12 CPU, 64 GB RAM).

Would it be feasible to colocate the Deployer with the DS + MC or the CM + LM? Or would you recommend that the Deployer be installed on a standalone instance?

Labels (2)
0 Karma

It is feasible to colocate the deployer on either of the instances you are considering. If you have more than 50 forwarders, however, put the deployer with the CM.
If this reply helps you, an upvote would be appreciated.