Deployment Architecture

DR Splunk indexer setup on AWS Cloud

Rim-unix
Engager

Hi Team, 

we are planning to build DR Splunk indexer on AWS Cloud.

could you give the detailed instructions for creating the DR Splunk indexer.

Thanks & Regards 

Ramamohan 

 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Rim-unix ,

good for you, see next time!

let us know if we can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Rim-unix ,

what do you mean with DR Indexers?

at first, I suppose that you have an Indexer Cluster, is it correct?

Anyway, you should design a multisite Indexer Cluster where the secondary site is on AWS.

To do this I hint to engage a Splunk PS or a certified Splunk Architect.

Ciao.

Giuseppe

0 Karma

Rim-unix
Engager

I suppose that you have an Indexer Cluster, is it correct?

No

,you should design a multisite Indexer Cluster where the secondary site is on AWS.

yes we are planning multisite Indexer Cluster. 
the DR site is US-WEST-2 (Oregon) .

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Rim-unix ,

if you have an Indexer Cluster, you can create a multisite Cluster and DR is automatic.

If you don't have an Indexer Cluster, you have to find a different way for DR, using external tools as Veeam or other products.

Ciao.

Giuseppe

0 Karma

Rim-unix
Engager

Thanks Giuseppe , your suggestions, we are planning the different way to build setup, if we have any query, we will get back to you. 

once again thanks Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you have single indexer you can migrate it to cluster and then multisite cluster quite easily. You can found those steps on 

You can create one node cluster if needed or use several nodes on site and of course same amount and size of nodes in DR site too.

Without this with other tool it will be more complicated to build DR and especially working DR site. So I strongly recommend to use Splunk's own way to do DR!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Rim-unix ,

good for you, see next time!

let us know if we can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

isoutamo
SplunkTrust
SplunkTrust
For DR purposes you should use multisite cluster option. See more
https://docs.splunk.com/Documentation/SVA/current/Architectures/M2M12
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...