Deployment Architecture

All-In-One configuration and clustering

gladieu1
Explorer

Dear Community,

We have the following question :

In the 'all-in-one' configuration (1 server holding : Forwarder+Indexer+SH), may we implement clustering, in order to insure redundancy and have two 'all-in-on' servers into two different location but in redundancy so data are secured if one site comes down ?

Thanks in advance,

Regards

0 Karma

somesoni2
Revered Legend

No. The clustering requires certain minimum number of nodes and requires those nodes perform specific roles only. So, having just two nodes may not be possible. Have a look at the Splunk documentation for clustering. It'll give you specifics about how many servers (and of what type/role) you need. You could create a cluster with bare minimum number of nodes.

https://docs.splunk.com/Documentation/Splunk/7.2.6/Indexer/Basicclusterarchitecture#Cluster_nodes

gladieu1
Explorer

Thanks very much for your answer and documentation, very much appreciated 🙂
It is very important to us to be about having 2 Indexers/peer nodes only. You mention it may not possible to have only two, and the documentation shows with 3 peers, you're right, but for me it is for the example purpose only ? Or it really must be greater or equal to 3 peers at least and so 2 peers cannot be implemented ??

thanks again,
Kind regards

0 Karma

gladieu1
Explorer

Nobody please ?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...