Deployment Architecture

DR Splunk indexer setup on AWS Cloud

Rim-unix
Engager

Hi Team, 

we are planning to build DR Splunk indexer on AWS Cloud.

could you give the detailed instructions for creating the DR Splunk indexer.

Thanks & Regards 

Ramamohan 

 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Rim-unix ,

good for you, see next time!

let us know if we can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Rim-unix ,

what do you mean with DR Indexers?

at first, I suppose that you have an Indexer Cluster, is it correct?

Anyway, you should design a multisite Indexer Cluster where the secondary site is on AWS.

To do this I hint to engage a Splunk PS or a certified Splunk Architect.

Ciao.

Giuseppe

0 Karma

Rim-unix
Engager

I suppose that you have an Indexer Cluster, is it correct?

No

,you should design a multisite Indexer Cluster where the secondary site is on AWS.

yes we are planning multisite Indexer Cluster. 
the DR site is US-WEST-2 (Oregon) .

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Rim-unix ,

if you have an Indexer Cluster, you can create a multisite Cluster and DR is automatic.

If you don't have an Indexer Cluster, you have to find a different way for DR, using external tools as Veeam or other products.

Ciao.

Giuseppe

0 Karma

Rim-unix
Engager

Thanks Giuseppe , your suggestions, we are planning the different way to build setup, if we have any query, we will get back to you. 

once again thanks Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you have single indexer you can migrate it to cluster and then multisite cluster quite easily. You can found those steps on 

You can create one node cluster if needed or use several nodes on site and of course same amount and size of nodes in DR site too.

Without this with other tool it will be more complicated to build DR and especially working DR site. So I strongly recommend to use Splunk's own way to do DR!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Rim-unix ,

good for you, see next time!

let us know if we can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

isoutamo
SplunkTrust
SplunkTrust
For DR purposes you should use multisite cluster option. See more
https://docs.splunk.com/Documentation/SVA/current/Architectures/M2M12
0 Karma
Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...

Enterprise Security Content Update (ESCU) | New Releases

In March, the Splunk Threat Research Team had 2 releases of security content via the Enterprise Security ...

Join the Splunk Developer Program Hackathon: Splunk Build-a-thon!

The Splunk Developer Program is launching in beta, and we’re celebrating with an exciting hackathon! This is ...