<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk cluster in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-cluster/m-p/41381#M1160</link>
    <description>&lt;P&gt;Thanks kristian&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2013 12:01:48 GMT</pubDate>
    <dc:creator>498773</dc:creator>
    <dc:date>2013-08-21T12:01:48Z</dc:date>
    <item>
      <title>Splunk cluster</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-cluster/m-p/41379#M1158</link>
      <description>&lt;P&gt;Please suggest the best practise for splunk deployment&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Considerations:&lt;/STRONG&gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Index data of size 2GB daily&lt;/LI&gt;
&lt;LI&gt;Data comes from 20 different hosts&lt;/LI&gt;
&lt;LI&gt;Report generation on data&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;&lt;STRONG&gt;Proposed Solution:&lt;/STRONG&gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;Search Factor=2, Replication Factor=2&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;20 forwarders to pull data from hosts&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;One master node, Two Peer Nodes(for Indexing) , One Search head&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Data on each node would be 1GB (considering RF and SF)&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;My question is does this set up looks good or can i avoid search head as there are only two indexers, please suggest some best practices . Do i really need to go for cluster set up if not what can be done ?????&lt;/P&gt;

&lt;P&gt;looking forward for your ideas, Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2013 10:26:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-cluster/m-p/41379#M1158</guid>
      <dc:creator>498773</dc:creator>
      <dc:date>2013-08-21T10:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cluster</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-cluster/m-p/41380#M1159</link>
      <description>&lt;P&gt;No, you don't &lt;EM&gt;need&lt;/EM&gt; to have a cluster. It's a design decision which will give you added fault tolerance. Given the rather small amount of data you're indexing, a single server will most likely satisfy your capacity needs (depending on the amount of searches you will actually be making - scheduled or manual). &lt;/P&gt;

&lt;P&gt;NB: with a cluster like you specified, the storage on each node will be 2GB daily, not 1GB, since you duplicate all your data (SF=2, RF=2). Thus it's 4GB spread over 2 indexers.&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2013 10:59:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-cluster/m-p/41380#M1159</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-08-21T10:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cluster</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-cluster/m-p/41381#M1160</link>
      <description>&lt;P&gt;Thanks kristian&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2013 12:01:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-cluster/m-p/41381#M1160</guid>
      <dc:creator>498773</dc:creator>
      <dc:date>2013-08-21T12:01:48Z</dc:date>
    </item>
  </channel>
</rss>

