Deployment Architecture

Can I run two Splunk instances on one physical server with one instance in a Search Head Cluster and the other in an Indexer Cluster?

Explorer

I am developing a Disaster Recover solution for my Splunk environment and only have four physical servers (all 32 CPU 128 GB memory) and two VMs.

I was hoping that I would be able to run two Splunk instances on one of the physical servers and have one instance in a Search Head Cluster and the other in an Indexer Cluster (Search and Replication factor of 2).

Unfortunately, I cannot find the answer in the documentation and I cannot test in the VM world.

0 Karma

Path Finder

Yes, I don't see why not. You certainly have enough machine there in terms of CPU and memory to accommodate multiple instances. The cluster (search heads and indexers) processes use different ports. So, that shouldn't be a problem. As long as you have enough storage and plan your installation carefully so that the two instances don't step on each other in terms of port assignments, you should be fine. I've worked with single servers running multiple instances in the way you describe before and they work just fine.

0 Karma