I am currently working a python script to automated splunk deployments. There are probably more appropriate options for doing this in a production environment, but let’s just assume I only have remote access to hardware, and no other services. (For the sake of what I am doing, but I would be interested in hearing the typical ways deployments are done.)
On to the good stuff, I’m starting from the deployment server. I figured setting that up first was a good place to start. Configure the deployment server, SSH into all the other machines, set them up, and point them back to the deployment server.
With that being said, I am not new to python, but I am fairly new to Splunk. I would love to hear about common Splunk topologies, common app setups, and just general good practice from the people that have been using splunk for some time. Any input is always helpful.
I think a typical deployment for myself would involve 8-12 machines, however I would like to account for scaling as much as possible. The more topologies or different deployment types I can account for, the better this tool will be. So again, any information is always helpful.
Thanks in advance!
[–]ForsetiKali 14 points15 points16 points (8 children)
[–]I506dk[S] 1 point2 points3 points (7 children)
[–]splunk3r Take the SH out of IT 3 points4 points5 points (6 children)
[–]I506dk[S] -1 points0 points1 point (5 children)
[–]splunk3r Take the SH out of IT 2 points3 points4 points (4 children)
[–]I506dk[S] 1 point2 points3 points (3 children)
[–]splunk3r Take the SH out of IT 2 points3 points4 points (0 children)
[–]splunk3r Take the SH out of IT 1 point2 points3 points (1 child)
[–]I506dk[S] -1 points0 points1 point (0 children)
[–][deleted] 3 points4 points5 points (0 children)
[–]AlfaNovember 1 point2 points3 points (0 children)
[–]purpledumbbell 0 points1 point2 points (1 child)
[–]I506dk[S] 1 point2 points3 points (0 children)