<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Replication/Cloning for HA architectures in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Replication-Cloning-for-HA-architectures/m-p/49180#M1531</link>
    <description>&lt;P&gt;As of Splunk 5.0, the recommended approach is Index Replication. &lt;/P&gt;

&lt;P&gt;More info &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/Aboutclusters"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/Aboutclusters&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Feb 2013 23:22:37 GMT</pubDate>
    <dc:creator>mahamed_splunk</dc:creator>
    <dc:date>2013-02-20T23:22:37Z</dc:date>
    <item>
      <title>Data Replication/Cloning for HA architectures</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Replication-Cloning-for-HA-architectures/m-p/49178#M1529</link>
      <description>&lt;P&gt;Using Splunk functionality, I see that you can enable data cloning/replication either by:&lt;/P&gt;

&lt;P&gt;a) configuring a forwarder to load balance over indexers in a primary cluster and also clone data to a indexers in a mirrored cluster&lt;/P&gt;

&lt;P&gt;b) configuring the primary indexer cluster to replicate data to a mirrored indexer cluster&lt;/P&gt;

&lt;P&gt;On the surface of things, I can't really see any glaringly major differences in either approach.&lt;/P&gt;

&lt;P&gt;Any advice on the recommended approach would be appreciated.&lt;/P&gt;

&lt;P&gt;DD.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2011 11:00:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Replication-Cloning-for-HA-architectures/m-p/49178#M1529</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2011-07-27T11:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Data Replication/Cloning for HA architectures</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Replication-Cloning-for-HA-architectures/m-p/49179#M1530</link>
      <description>&lt;P&gt;Benefits of B:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;It ensures that datasets on primary and mirrored indexers are identical (if one indexer goes down in cloning situation, it may miss events while the other continues to accept them).&lt;/LI&gt;
&lt;LI&gt;Moves extra resource usage (network traffic, cpu cycles) due to dealing with HA from the forwarder (where you probably don't want to interfere with your apps' performance) to the indexer.&lt;/LI&gt;
&lt;LI&gt;You have the option to tweak what is and isn't forwarded between the primary and mirrored indexers if you want to for some reason. Option A is just a blind clone.&lt;/LI&gt;
&lt;LI&gt;Probably some other reasons I don't know about! I know for a fact that HA using autoLB on forwarders and then forwarding data from the indexer(s) is now the official recommendation over the old recommendation of using cloning on the forwarders (according to our Splunk consultants and workshops at a SplunkLive event).&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 13 Oct 2011 12:38:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Replication-Cloning-for-HA-architectures/m-p/49179#M1530</guid>
      <dc:creator>Glenn</dc:creator>
      <dc:date>2011-10-13T12:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Data Replication/Cloning for HA architectures</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Replication-Cloning-for-HA-architectures/m-p/49180#M1531</link>
      <description>&lt;P&gt;As of Splunk 5.0, the recommended approach is Index Replication. &lt;/P&gt;

&lt;P&gt;More info &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/Aboutclusters"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/Aboutclusters&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Feb 2013 23:22:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Replication-Cloning-for-HA-architectures/m-p/49180#M1531</guid>
      <dc:creator>mahamed_splunk</dc:creator>
      <dc:date>2013-02-20T23:22:37Z</dc:date>
    </item>
  </channel>
</rss>

