Hello Splunkers.. I need urgent assistance in setting up Splunk ITSI. Our current Infrastructure is a distributed one running on Splunk version 6.0.1.
Present Infrastructure where Splunk 6.0.1 is present:-
Two indexers - RAM 16 GB, CPU 12 CORES
Two search heads(SHP) - RAM 16 GB, CPU 12 CORES
One Cluster master - RAM 16 GB, CPU 12 CORES
We want to install Splunk ITSI and for that we have ordered completely new VM which will behave as a dedicated Search head for ITSI. Can someone please clarify my doubts:-
1) For 100-200 KPIs the VM I ordered has specs RAM 32 GB, CPU 16 CORES, Disc 500 GB
Also i will upgrade present Indexers specs to RAM 32 GB, CPU 16 CORES.
2) Version upgrade. Can we run Splunk ITSI search head on version 7.1.x and what minimum version we need to upgrade for present Indexer, Search heads and CM.
3) We dont`t want to load Search heads so that`s why we have ordered new VM as dedicated search head. Is it good approach ?
Thanks,
Ramprakash
↧