Components that help to manage your deployment
Management components support the activities of the processing components. As with processing components, management components are specially configured versions of Splunk Enterprise instances.
Types of management components
A deployment usually includes one or more of these management components:
- The license manager handles Splunk Enterprise licensing.
- The monitoring console performs centralized monitoring of the entire deployment.
- The deployment server updates configurations and distributes apps to processing components, primarily forwarders.
- The indexer cluster managernode, sometimes referred to as the "cluster manager", coordinates the activities of an indexer cluster. It also handles updates for indexer clusters.
- The search head cluster deployer handles updates for search head clusters.
Whether to colocate management components
Depending on the component and its workload, you might be able to combine two management components on a single Splunk Enterprise instance. In some cases, you can locate a management component on an instance with a processing component.
In some low-use situations, you might be able to combine more than two management components on a single instance, although it is not generally recommended that you do so. If you intend to do so, monitor the performance impacts closely to ensure that you are not overloading the instance.
The following table summarizes the colocation possibilities, under ideal circumstances, for each management component type. Be sure also to read the disclaimer that follows the table, as it contains important guidelines on how to use the table.
Key: "LM" = license manager; "MC" = monitoring console; "DS" = deployment server; "CM" = cluster manager.
Management component | Colocate with | ||||||
LM? | MC? | DS? | CM? | Deployer? | Indexer? | Search head? | |
License manager | - | yes | yes | yes | yes | yes | yes |
Monitoring console | yes | - | yes | yes | yes | no | yes |
Deployment server | yes | yes | - | no | yes | yes | yes |
Indexer cluster manager node | yes | yes | no | - | yes | no | no |
Search head cluster deployer | yes | yes | yes | yes | - | no | no |
Do not use this table without further study of each component type. Some combinations are valid only within limited constraints.
Whether any two components in your deployment can actually be colocated depends on a number of factors, including the overall load on each component and your specific deployment topology. For that reason, you must read the colocation documentation for each component and follow the guidelines in that documentation.
In particular, both the deployment server and the cluster manager have strict resource limits. If you exceed those limits, you cannot colocate any other component type with either of them.
For more information on colocating a specific management component, see the documentation for that component:
- For the license manager, see Configure a license manager in the Admin Manual.
- For the monitoring console, see Which instance should host the console? in Monitoring Splunk Enterprise.
- For the deployment server, see Deployment server and other roles in the Updating Splunk Enterprise Instances manual.
- For the cluster manager, see Additional roles for the manager node in the Managing Indexers and Clusters of Indexers manual.
- For the deployer, see Deployer requirements in the Distributed Search manual.
Components and the data pipeline | Key manuals for a distributed deployment |
This documentation applies to the following versions of Splunk® Enterprise: 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.1.7, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.3.0, 9.3.1, 9.3.2, 9.4.0
Feedback submitted, thanks!