All Apps and Add-ons

What is the DR approach of Splunk ES on AWS?

keffen611
New Member

Hi everyone,

Assume the best practices of Splunk AWS is deployed on production AWS region (e.g. London).
How to design the DR of Splunk?
1. create another best practice design in another region (e.g. Paris) and extend the SH cluster and indexer cluster to the Paris region?
2. what if a hot-stanby is no required, is it able to take a whole of the Splunk (including VPC, AZ, subnets, Security groups, instances, EBS) and archive it in S3 bucket and restore it in Paris region manually?

Best Practice Architecture:
https://aws.amazon.com/quickstart/architecture/splunk-enterprise/

Thanks.

0 Karma

woodcock
Esteemed Legend

This is a HUGE questions. What parts do you nee DRd? How much downtime can you have? Do you have budget/constraints?

0 Karma

adonio
Ultra Champion

the real question is, what is the problem you are trying to solve?
what is it you would like to protect against?
do you need DR for your search components? Index (data) components?
do you need HA?
Please share what is it that you would like to achieve

0 Karma

keffen611
New Member

if the primary AWS region is down, we have to resume the SIEM in another AWS region within 4 hours.
no HA between AWS region is needed.
HA is required within same AWS region.
I need DR for search components and index components as the applications will also failover to the DR AWS region.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...