Deployment Architecture

Deployment

BrC_Sys99
Loves-to-Learn

Was given the incorrect information on last post.

Our Splunk is On-Prem and we want to migrate to the Cloud. 

Will we be given the option to use On-Prem and cloud as a hybrid when migrating ? 

Also options for forwarding redundancy during migration?  

 

Thank you 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @BrC_Sys99,

what do you mean with "Hybrid during migration"?

if you mean sending logs both the Splunk Cloud and On-Premise, it's easy.

If you have some infrastructures on premise, it's a best practice to use one (or better two) Heavy Forwarder as a concentrator of all the logs from on-premise infrastructure.

In this way you don't need to open firewall routes between all your servers and applianes and Splunk Cloud. but you must open only the routes netween the two Heavy Forwarders and Splunk Cloud.

Using this architecture, you could create (on the HFs) a fork that duplicates data flows sending all data both to the old on-premise indexers and to the Splunk Cloud.

When migration will finish, you'll remove the fork and you'll have all the logs only on Splunk Cloud and you'll be able to dismiss the old Splunk infrastructure.

The only role that you must maintain of the old infrastructure is the Deployment Server if you have more than 50 clients to manage.

Ciao.

Giuseppe

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk Hybrid Search has been replaced by Federated Search (FS).  It allows you to search both your local and Cloud indexes from the same search head.  There are plenty of caveats to FS so I don't recommend it for general use.

You can, and this is very common, send your data to both your local indexers and to Splunk Cloud indexers at the same time.  That lets you use your on-prem system for historical searches while populating Splunk Cloud with data for a future cutover.

Finally, it's also possible to transfer your data from your on-prem indexers to Splunk Cloud and switch over immediately to using Cloud.  That, however, requires Splunk Professional Services.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...