Splunk® SOAR (On-premises)

Install and Upgrade Splunk SOAR (On-premises)

Acrobat logo Download manual as PDF


The classic playbook editor will be deprecated soon. Convert your classic playbooks to modern mode.
After the future removal of the classic playbook editor, your existing classic playbooks will continue to run, However, you will no longer be able to visualize or modify existing classic playbooks.
For details, see:
This documentation does not apply to the most recent version of Splunk® SOAR (On-premises). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Create a cluster using a privileged installation

Build a cluster, putting each of the services on its own server or group of servers to serve multiple cluster nodes of .

Number Task Description
1 Create the HAProxy server. Use the HAProxy server to be a load balancer for the nodes in your cluster. See Set up a load balancer with an HAProxy server.
2 Create the PostgreSQL server or cluster. Establish a PostgreSQL database server or cluster to store information. See Set up an external PostreSQL server.
3 Create the file shares server. will store all its shared files on the prepared GlusterFS server. You can use NFS or other network file system. Instructions for that are not included in this document. See Set up external file shares using GlusterFS.
4 Install Splunk Enterprise. will use Splunk Enterprise for searches and collect data for indexing using the HTTP Event Collector. See Set up Splunk Enterprise.
5 Install cluster nodes.
  1. Install using the TAR file method for unprivileged installs. Do this once for each node you need in your cluster. See Install as a privileged user or Install as an unprivileged user.
  2. Make the first node with make_cluster_node.pyc. See Run make_cluster_node.pyc.
  3. Make additional nodes.
Last modified on 19 September, 2023
PREVIOUS
About clusters
  NEXT
Create a cluster using an unprivileged installation

This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.3.1, 5.3.2, 5.3.3, 5.3.4, 5.3.5


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters