Deployment Architecture

Cross Cluster Search - Single site vs Multisite

mufthmu
Path Finder

Hi,

I have a task where I need to make my search head cluster to be able to search from two different data center/indexer clusters. One in east and another one in west coast.

According to the docs below: this can be done in 2 ways; single-site or multisite:
https://docs.splunk.com/Documentation/Splunk/6.3.3/Indexer/Configuremulti-clustersearch

I have some ideas of how both work but I need more in-depth explanation why one approach is better than the other (in terms of searching/indexing performance, latency, cost, maintenance, complexity, etc). I do need to bring up that I will enable Smartstore to store data to AWS S3 instead of locally in indexer nodes.

Thank you so much in advance!

 

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The document provides instructions for setting up a SHC to search more than one indexer cluster.  Choose the instructions that pertain to your existing architecture.  There is no need to change your indexers or how they are clustered.

Also, SmartStore has no bearing on cross-cluster searching.  S2 is transparent to the search heads.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mufthmu
Path Finder

Hi @richgalloway 

Thank you for your prompt answer. 

I agree that I don't need to change my indexer cluster. But the documentation only talked about how to set that up and not about the comparison of the two. I just need more help to decide which one to pick.

Also, regarding your statement "Also, SmartStore has bearing on cross-cluster searching.  S2 is transparent to the search heads." Could you please elaborate more on this?

thanks!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Since you must already have indexers in your environment, choose the instructions that correspond to your indexer architecture.  IOW, if you have a cluster manager then use it; otherwise, use individual indexers.

I left out a crucial word in my SmartStore statement.  S2 has NO bearing on how you set up distributed search.  Search heads ask indexers to search for data - they don't know or care about how the indexers obtain that data.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...