Deployment Architecture

All-In-One configuration and clustering

gladieu1
Explorer

Dear Community,

We have the following question :

In the 'all-in-one' configuration (1 server holding : Forwarder+Indexer+SH), may we implement clustering, in order to insure redundancy and have two 'all-in-on' servers into two different location but in redundancy so data are secured if one site comes down ?

Thanks in advance,

Regards

0 Karma

somesoni2
Revered Legend

No. The clustering requires certain minimum number of nodes and requires those nodes perform specific roles only. So, having just two nodes may not be possible. Have a look at the Splunk documentation for clustering. It'll give you specifics about how many servers (and of what type/role) you need. You could create a cluster with bare minimum number of nodes.

https://docs.splunk.com/Documentation/Splunk/7.2.6/Indexer/Basicclusterarchitecture#Cluster_nodes

gladieu1
Explorer

Thanks very much for your answer and documentation, very much appreciated 🙂
It is very important to us to be about having 2 Indexers/peer nodes only. You mention it may not possible to have only two, and the documentation shows with 3 peers, you're right, but for me it is for the example purpose only ? Or it really must be greater or equal to 3 peers at least and so 2 peers cannot be implemented ??

thanks again,
Kind regards

0 Karma

gladieu1
Explorer

Nobody please ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...