Deployment Architecture

What to do with old splunk server?

tcary99
New Member

We have a single Splunk Enterprise server deployment. Recently, we migrated it to newer hardware (SSD drives, etc). The old machine is still a decent piece of equipment, just has less disk space. I've been reading about clustering, or adding an indexer. Would like to make use of the old machine for additional index storage and search, but it seems not worth doing a cluster with only two machines. Also, if I just added an indexer role, I have concerns about re-pointing forwarders there, etc. Any ideas? Anyone else been through something similar, where your older machine had not been "stolen" away and you can make use of it? Thanks in advance!

0 Karma

johnvr
Path Finder

This'll vary greatly depending on your needs, your users, and your environment (especially in comparison to your volume).

First, you can't cluster two indexers without adding a third appliance, a Cluster Master, but you can still employ it as a search peer -
non-clustered indexer - to balance the load.

A couple other ideas...

  • Offload smaller roles, like License Manager or Deployment Server, onto it.
  • Create a dedicated DMC
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...