Create a Splunk Phantom cluster from an RPM or TAR file installation
Build a cluster, putting each of the services on its own server or group of servers to serve multiple cluster nodes of Splunk Phantom.
Number | Task | Description |
---|---|---|
1 | Create the HAProxy server. | Use the HAProxy server to be a load balancer for the Splunk Phantom nodes in your cluster. See Set up a load balancer with an HAProxy server. |
2 | Create the PostgreSQL server or cluster. | Establish a PostgreSQL database server or cluster to store Splunk Phantom information. See Set up an external PostreSQL server. |
3 | Create the file shares server. | Splunk Phantom will store all its shared files on the prepared GlusterFS server. You can use NFS or other network file system. Instructions for that are not included in this document. See Set up external file shares using GlusterFS. |
4 | Install Splunk Enterprise. | Splunk Phantom will use Splunk Enterprise for searches and collect data for indexing using the HTTP Event Collector. See Set up Splunk Enterprise. |
5 | Install Splunk Phantom cluster nodes. |
|
Create a Splunk Phantom Cluster from an OVA installation | Create a Splunk Phantom cluster using an unprivileged installation |
This documentation applies to the following versions of Splunk® Phantom (Legacy): 4.8, 4.9, 4.10, 4.10.1, 4.10.2, 4.10.3, 4.10.4, 4.10.6, 4.10.7
Feedback submitted, thanks!