Deployment Architecture

Splunk server roles

splunkreal
Motivator

Hello,

could you explain me in details the possible roles of cluster member below and what would you advice for :

2 search heads
2 indexers
1 management console (cluster master at least, deployment server & SHC deployer?)

alt text

Thanks a lot.

* If this helps, please upvote or accept solution 🙂 *
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi realsplunk,
I suggest to read http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Basicclusterarchitecture and http://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/SHCarchitecture

Anyway in Search Head cluster you have:

  • Search Head Captain
  • Search Heads
  • Deployer: manage replication between SHs

Note that in Search Head Cluster you must have at least 3 SHs.

In Indexer Cluster you have

  • Search Peers (at least 2)
  • Master Node

Deployment Server must be a dedicated server if you have to manage more than 50 Forwarders

Bye.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi realsplunk,
I suggest to read http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Basicclusterarchitecture and http://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/SHCarchitecture

Anyway in Search Head cluster you have:

  • Search Head Captain
  • Search Heads
  • Deployer: manage replication between SHs

Note that in Search Head Cluster you must have at least 3 SHs.

In Indexer Cluster you have

  • Search Peers (at least 2)
  • Master Node

Deployment Server must be a dedicated server if you have to manage more than 50 Forwarders

Bye.
Giuseppe

splunkreal
Motivator

Thanks cusello, however why 3 SHs are required? Is there any doc on this requirement?

* If this helps, please upvote or accept solution 🙂 *
0 Karma

gcusello
SplunkTrust
SplunkTrust
0 Karma

splunkreal
Motivator

Thank Giuseppe, we use virtual machines FYI but yes I just read 3 SHs are better in case one search head fails.

* If this helps, please upvote or accept solution 🙂 *
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...