All Apps and Add-ons

Configure Splunk in HA

sureshsala
Explorer

Requirement:

I have two Splunk servers: serverA and serverB
splunk.example.com points to serverA and serverB
When serverA fails, it redirects to serverB. How can I configure the following
1. Data to be in sync on both the servers
2. Alerts should be in sync. It should not alert twice.

Splunk HA in Active-Passive Mode

0 Karma

woodcock
Esteemed Legend

This sounds like you are asking about a Search Head Cluster:

http://docs.splunk.com/Documentation/Splunk/6.4.0/DistSearch/SHCarchitecture

0 Karma

jmallorquin
Builder

Hi,

You need to make a cluster with a search head it will be send the alerts querying the to indexers. You will need an other sever with master role and other with search head role.

Hope i help you

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...