Deployment Architecture

create/add splunk search head cluster to existing index cluster (with working search heads)

bryanwiggins
Path Finder

[env]
centos 7, splunk enterprise 6.4.1
4x search heads (-mode searchhead -master_uri cluster_master) [2 heads are set to be decommissioned]
3x clustered index peers (cluster master) <- multi site capable, 1 site live for now
2x heavy forwarders
load balanced reverse proxy serving search head pool url access for users

question:
i am in the process of researching implementing a search head cluster in the current model (see [env] above) and have been looking at the following documentation; http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCdeploymentoverview

1: am i able to use 3 search head nodes that are already pointing the the back-end index cluster and then just run the commands to add these members to the search head cluster (and elect a captain) <- also add the deployer role to the index cluster master?

2: if no to No.1 do I create 3x new nodes as search heads, then create the search head cluster and a separate deployer node - if so, how best do i point these to use the index cluster peers?

I'm going to running this up in a lab, so I will update progress but if anyone has any initial guidance/pointers, that would be very much appreciated.

Thx
Bry

Tags (1)
0 Karma
1 Solution

bryanwiggins
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

followed the guide above and results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

View solution in original post

bryanwiggins
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

followed the guide above and results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

bryanwiggins
Path Finder

also saw this link in the document about integrating shc with an idxc; http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/SHCandindexercluster

0 Karma

bryanwiggins
Path Finder

looking more like i create the shc then add to the idx cluster.

0 Karma

bryanwiggins
Path Finder

i have a multi-node splunk lab setup now (to emulate my ^^^[env]). i will post my findings here once i have fully tested the options.

0 Karma

bryanwiggins
Path Finder

ok, results from lab test seemed to work fine. I was able to do the following:

  • config a deployer (on cluster master)
  • run the shcluster config on what would be the members (these were the existing search heads)
  • bootstrap a member to be the captain

I haven't seen any errors yet and I was able to still search the previous indexed data.

Thx
Bry

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...