Splunk® Phantom

Install and Upgrade Splunk Phantom

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Phantom. Click here for the latest version.
Acrobat logo Download topic as PDF

Create a Splunk Phantom cluster using an unprivileged installation

Build a cluster, putting each of the services on its own server or group of servers to serve multiple cluster nodes of Splunk Phantom.

Set up each of the external services either as the root user or a user with sudo permissions.

Install Splunk Phantom as an unprivileged user. In your cluster, each Splunk Phantom instance must have the same custom username and install directory. See Install Splunk Phantom as an unprivileged user.

Number Task Description
1 Create the HAProxy server. Use the HAProxy server to be a load balancer for the Splunk Phantom nodes in your cluster. See Set up a load balancer with an HAProxy server. There are additional steps to configure your load balancer to handle your custom HTTPS port for unprivileged clusters.
2 Create the PostgreSQL server. Establish a PostgreSQL database server or cluster to store Splunk Phantom information. See Set up the external PostreSQL server.
3 Create the file shares server. Splunk Phantom will store all its shared files on the prepared GlusterFS server. You can use NFS or other network file system. Instructions for that are not included in this document. See Set up external file shares using GlusterFS.
4 Create the Splunk Enterprise server. Splunk Phantom will use Splunk Enterprise for searches and collect data for indexing using the HTTP Event Collector. See Set up Splunk Enterprise.
5 Install Splunk Phantom cluster nodes.
  1. Install Splunk Phantom using the tar file method for unprivileged installs. Do this once for each node you need in your cluster. See Install Splunk Phantom as an unprivileged user.
  2. Make the first node with make_cluster_node.pyc. See Run make_cluster_node.pyc.
  3. Make additional nodes.
Last modified on 06 November, 2020
PREVIOUS
Create a Splunk Phantom cluster from an RPM or TAR file installation
  NEXT
Create a Splunk Phantom Cluster in Amazon Web Services

This documentation applies to the following versions of Splunk® Phantom: 4.8, 4.9


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters