Deployment Architecture

Impact of shutting down some splunk roles for a day?

jdmclemore
Path Finder

I have a 5 node indexer cluster and a 3 node SHC which are all physical servers, but the rest are VMs (Deployment server, License Server, Deployer, Master Cluster node, and DMC).

My VMs will be migrating to another network and will require downtime of about a day. I would like to leave the search heads and indexers up to continue collecting data during the outage. Is this possible? What impact will shutting down all those other servers have?

Tags (1)
0 Karma
1 Solution

lguinn2
Legend

If properly configured, the search heads and indexers should continue to operate for 24 hours without the other servers online.

That said, it would be much better if the outage was shorted. For example, when the Cluster Master Node comes back online, the cluster will need to "catch up" on the missed replication. Therefore, the longer the outage, the longer the "recovery."

I would prioritize the servers in this order:
Master Node
Monitoring Console
License Master
Deployment Server
Deployer

View solution in original post

0 Karma

lguinn2
Legend

If properly configured, the search heads and indexers should continue to operate for 24 hours without the other servers online.

That said, it would be much better if the outage was shorted. For example, when the Cluster Master Node comes back online, the cluster will need to "catch up" on the missed replication. Therefore, the longer the outage, the longer the "recovery."

I would prioritize the servers in this order:
Master Node
Monitoring Console
License Master
Deployment Server
Deployer

0 Karma

jdmclemore
Path Finder

Thank you!

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...