<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk high availability failover and loadbalancers in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-high-availability-failover-and-loadbalancers/m-p/80901#M2880</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We are setting up our splunk environment up with a loadbalancer with a failover search head and have found this article that discusses rsync to keep our search heads up to date together &lt;A href="http://wiki.splunk.com/Community:HighAvailabilityAndSplunk"&gt;http://wiki.splunk.com/Community:HighAvailabilityAndSplunk&lt;/A&gt;. &lt;/P&gt;

&lt;P&gt;A couple questions come up with this though...&lt;/P&gt;

&lt;P&gt;1) Are there any other files that should be rsynced other than whats mentioned?&lt;BR /&gt;
2) For certain .conf files that have a hashed password how do we overcome syncing these files and allowing the secondary instance to decrypt the passwords?&lt;BR /&gt;
3) Would you even recommend using loadbalancers in this fashion with rysnc? If not, any alternatives/recommendations?&lt;BR /&gt;
4) Any considerations that I may be missing? &lt;/P&gt;

&lt;P&gt;Right now we have about 30 users on one search head but would like our deployment to be scalable and resilient.&lt;/P&gt;

&lt;P&gt;Thanks for the help!   &lt;/P&gt;</description>
    <pubDate>Mon, 01 Jul 2013 13:51:07 GMT</pubDate>
    <dc:creator>aaronkorn</dc:creator>
    <dc:date>2013-07-01T13:51:07Z</dc:date>
    <item>
      <title>Splunk high availability failover and loadbalancers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-high-availability-failover-and-loadbalancers/m-p/80901#M2880</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We are setting up our splunk environment up with a loadbalancer with a failover search head and have found this article that discusses rsync to keep our search heads up to date together &lt;A href="http://wiki.splunk.com/Community:HighAvailabilityAndSplunk"&gt;http://wiki.splunk.com/Community:HighAvailabilityAndSplunk&lt;/A&gt;. &lt;/P&gt;

&lt;P&gt;A couple questions come up with this though...&lt;/P&gt;

&lt;P&gt;1) Are there any other files that should be rsynced other than whats mentioned?&lt;BR /&gt;
2) For certain .conf files that have a hashed password how do we overcome syncing these files and allowing the secondary instance to decrypt the passwords?&lt;BR /&gt;
3) Would you even recommend using loadbalancers in this fashion with rysnc? If not, any alternatives/recommendations?&lt;BR /&gt;
4) Any considerations that I may be missing? &lt;/P&gt;

&lt;P&gt;Right now we have about 30 users on one search head but would like our deployment to be scalable and resilient.&lt;/P&gt;

&lt;P&gt;Thanks for the help!   &lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2013 13:51:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-high-availability-failover-and-loadbalancers/m-p/80901#M2880</guid>
      <dc:creator>aaronkorn</dc:creator>
      <dc:date>2013-07-01T13:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk high availability failover and loadbalancers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-high-availability-failover-and-loadbalancers/m-p/80902#M2881</link>
      <description>&lt;P&gt;Can't help with the other bits as we're running search head pooling ourselves but the shared secret part of the following link might be useful for point 2: &lt;A href="http://wiki.splunk.com/Community:How_to_add_a_search_head_to_your_pool"&gt;http://wiki.splunk.com/Community:How_to_add_a_search_head_to_your_pool&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2013 14:01:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-high-availability-failover-and-loadbalancers/m-p/80902#M2881</guid>
      <dc:creator>samhughe</dc:creator>
      <dc:date>2013-07-01T14:01:08Z</dc:date>
    </item>
  </channel>
</rss>

