Deployment Architecture

Adding new SH cluster to existing splunk setup.

sajeshpp
Path Finder

Currently we have 1 multisite indexing cluster, 1 multisite search head cluster, a deployer and a master node.
Planning to add one more search head cluster which will have same configuration as existing SH cluster.
So we will be using same deployer and indexing cluster with this new cluster.
1. What are the configuration changes required in deployer If it manage multiple SH clusters. ?
2.What will be the deference in existing SH member and new cluster members ?
I could not find any splunk docs to find what is the difference in deployer configuration when it mange single cluster and multiple clusters.

Basically the requirement will be to have a splunk setup with
1 Multisite Indexing cluster, 2 Multisite SH cluster, 1 Master node and a deployer.

Tags (1)
0 Karma

somesoni2
Revered Legend

A deployer can't manage multiple SH cluster. You would need a separate deployer node. It however, can co-exist with your indexer cluster-master node, provided there is not too much load on cluster-master and it has sufficient h/w resource. So you can either add a new deployer node OR setup your cluster master as deployer for new SHC.

0 Karma

sajeshpp
Path Finder

As per splunk documentation they says you can use same deployer for all clusters if it employ same configuration.
"
Deploy to multiple clusters
The deployer sends the same configuration bundle to all cluster members that it services. Therefore, if you have multiple search head clusters, you can use the same deployer for all the clusters only if the clusters employ exactly the same configurations, apps, and so on.

If you anticipate that your clusters might need different configurations over time, set up a separate deployer for each cluster "

http://docs.splunk.com/Documentation/Splunk/6.6.2/DistSearch/PropagateSHCconfigurationchanges#Deploy...

But I dont see the deployer configuration differences when it serves for single cluster and multiple cluster in splunk documentation.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...