<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SPLUNK Architecture Deployment Minimal (Recommendations) in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411022#M20980</link>
    <description>&lt;P&gt;Yes I think the single search head replicated to a standby might be the way to go. Will investigate index cluster with a rf of 2 and vm replication of an unclustered search head.&lt;/P&gt;</description>
    <pubDate>Sat, 20 Apr 2019 09:23:33 GMT</pubDate>
    <dc:creator>willadams</dc:creator>
    <dc:date>2019-04-20T09:23:33Z</dc:date>
    <item>
      <title>SPLUNK Architecture Deployment Minimal (Recommendations)</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411015#M20973</link>
      <description>&lt;P&gt;We currently use a single SPLUNK Enterprise server that runs on a single virtual machine on ESXi.  This instance is both our search and index device.  It has been running quite solidly for a while now, but we are looking at a way to effectively provide DR/HA as this will likely become our SIEM in the long term.  The single instance has SSD disk and has 8 vCPU dedicated to the machine (CPU's are Intel with a clock speed of 3.4Ghz).&lt;/P&gt;

&lt;P&gt;Every time I look at redesigning this server for DR, I end up with a design that will cost a small fortune in just the hardware alone, especially taking into consideration this may become the primary SIEM over time.  I need the server to be highly available as during a incident this becomes critical for us.&lt;/P&gt;

&lt;P&gt;I would initially need 2 indexers (1 at each site) and potentially 1 or 2 search heads.  However SPLUNK doco says that I must have a minimum search head cluster of 3.  If I read the SPLUNK doco right and I buy say a 2 x 12 core ESXi hosts with dedicated vCPU, this alone means that I would need to purchase 4 or 5 hosts to manage this load.  &lt;/P&gt;

&lt;P&gt;This is not a financially viable option.  Another thought might be to just have a single search head (not clusterd) with 2 indexers (an indexer and search head on 1 ESXi host) and then have another indexer on the DR host.  This would be 2 hosts rather than 5.  I could in theory then just use ESXi replication for the search head (and avoid the SRM costs and infrastructure).  Would this be a viable alternative?&lt;/P&gt;

&lt;P&gt;The amount of data we currently ingest is around 30GB, but this will ramp up quite quickly.  Over time I also need to make consideration for expansion/growth.  We are looking at cloud, but at the moment the focus is just on an on-premise model.&lt;/P&gt;

&lt;P&gt;Thoughts?  Appreciate any responses.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 13:06:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411015#M20973</guid>
      <dc:creator>willadams</dc:creator>
      <dc:date>2019-04-18T13:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK Architecture Deployment Minimal (Recommendations)</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411016#M20974</link>
      <description>&lt;P&gt;The documentation is correct that you need 3 nodes for a search head cluster. That is the only way to avoid split-brain situations.&lt;BR /&gt;
However, clustering your search heads is &lt;EM&gt;not&lt;/EM&gt; required. There is no reason you can't have one to many individual search heads attached to your indexers. Though they may be doing duplicate work as your search artifacts will not be replicated.&lt;/P&gt;

&lt;P&gt;Based on the description of your requirements I would suggest that your environment is a prime candidate for running Splunk in containers. That topology will require less hardware while allowing you to scale, minimize resources, and also realize high availability.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 13:59:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411016#M20974</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2019-04-18T13:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK Architecture Deployment Minimal (Recommendations)</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411017#M20975</link>
      <description>&lt;P&gt;I might look into the additional unclustered  search heads option and see where that leads. I did look at docker to run Splunk in containers but wasnt sure on the ha/dr options I have there (dont know the intricacies of docker)&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 15:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411017#M20975</guid>
      <dc:creator>willadams</dc:creator>
      <dc:date>2019-04-18T15:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK Architecture Deployment Minimal (Recommendations)</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411018#M20976</link>
      <description>&lt;P&gt;There are many solutions for implementing container orchestration with Docker. It just depends on what you want to accomplish and what you feel comfortable with. &lt;/P&gt;

&lt;P&gt;The most popular options would be Kuberenetes (my favorite), DC/OS, and Docker Swarm.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 18:33:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411018#M20976</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2019-04-18T18:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK Architecture Deployment Minimal (Recommendations)</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411019#M20977</link>
      <description>&lt;P&gt;But isn't Docket only supported for an S1 type SVA?  There doesn't look to have been any further updates with potentially doing something like a D1 SVA deployment.  We have a layer 2 network between our primary and secondary site, so conceivably I could look at this as a single site deployment and have 2 indexes clustered potentially with a single search head.  The search head could just be replicated.  I will try and experiment with docker and see where that goes (although this will be a new implementation of something unknown but be good from a learning exercise).  &lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2019 01:06:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411019#M20977</guid>
      <dc:creator>willadams</dc:creator>
      <dc:date>2019-04-19T01:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK Architecture Deployment Minimal (Recommendations)</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411020#M20978</link>
      <description>&lt;P&gt;@willadams have you referred to &lt;A href="https://www.splunk.com/pdfs/technical-briefs/splunk-validated-architectures.pdf"&gt;Splunk Validated Architectures&lt;/A&gt;. You can check out .Conf Session &lt;A href="https://conf.splunk.com/conf-online.html?search.event=conf18&amp;amp;search=FN1151#/"&gt;The Hitchhiker's Guide to Splunk Validated Architectures&lt;/A&gt;, for understanding what this document is all about.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2019 05:31:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411020#M20978</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2019-04-19T05:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK Architecture Deployment Minimal (Recommendations)</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411021#M20979</link>
      <description>&lt;P&gt;The cheapest HA/DR option will be to convert your storage to &lt;CODE&gt;SS&lt;/CODE&gt;/&lt;CODE&gt;S3&lt;/CODE&gt; (HA cloud storage), create a stand-by, non-clustered Search Head with periodic manual sync of &lt;CODE&gt;apps&lt;/CODE&gt; and &lt;CODE&gt;users&lt;/CODE&gt; directories.  In your case, a Search Head Cluster is overkill and definitely not worth the hassle.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2019 13:10:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411021#M20979</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-04-19T13:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK Architecture Deployment Minimal (Recommendations)</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411022#M20980</link>
      <description>&lt;P&gt;Yes I think the single search head replicated to a standby might be the way to go. Will investigate index cluster with a rf of 2 and vm replication of an unclustered search head.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2019 09:23:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411022#M20980</guid>
      <dc:creator>willadams</dc:creator>
      <dc:date>2019-04-20T09:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK Architecture Deployment Minimal (Recommendations)</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411023#M20981</link>
      <description>&lt;P&gt;Can I do the following without much of an issue.&lt;/P&gt;

&lt;P&gt;Stand up 2 indexers and a single search head. Obviously this is just splunk enterprise installed on each. So I would have &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;VM with an indexer oni it&lt;/LI&gt;
&lt;LI&gt;VM with an indexer on it (this would be on seperate ESXi host)&lt;/LI&gt;
&lt;LI&gt;VM acting as a search head (this would then be replicated to DR).&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Storage I was going to have on local disk (ssd) on each host. &lt;/P&gt;

&lt;P&gt;This way I could have an index cluster with a rf of 2 so my data is in 2 spots and I just configure the search head to search across both.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2019 09:44:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411023#M20981</guid>
      <dc:creator>willadams</dc:creator>
      <dc:date>2019-04-20T09:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK Architecture Deployment Minimal (Recommendations)</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411024#M20982</link>
      <description>&lt;P&gt;This should work OK but you also need a Cluster Master node.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2019 20:06:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411024#M20982</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-04-21T20:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK Architecture Deployment Minimal (Recommendations)</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411025#M20983</link>
      <description>&lt;P&gt;HI @willadams &lt;/P&gt;

&lt;P&gt;Looks like you have a few possible solutions to your question. If one of them provided a working solution, please don't forget to click "Accept" below the best answer to resolve this post. If you still need help, please leave a comment. Don’t forget to upvote anything that was helpful too. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 16:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SPLUNK-Architecture-Deployment-Minimal-Recommendations/m-p/411025#M20983</guid>
      <dc:creator>Anam</dc:creator>
      <dc:date>2019-04-24T16:58:11Z</dc:date>
    </item>
  </channel>
</rss>

