Deployment Architecture

Help on Splunk deployment plan

jg91
Path Finder

Hello friends,
We want to deploy splunk in a new site and we have 2 powerful server with SSD storage, We need to have data high availability and our current plan is to install one indexer on each server and use 1 Heavy Forwarder on 3rd server to send data to both indexers.
Is this plan good enough or there is a better plan like using indexer clustering and install cluster master on 3rd server?
Please share your suggestions with me about deployment architecture with 2 server.
Thanks,

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Use an indexer cluster to replicate your data.

Forcing a HF to send data to two indexers creates more problems than it solves. Your license will be hit twice. Your searches will return duplicate results. Any failure to connect to indexer (like during maintenance) means your data is no longer in two places. Clustering resolves all of these issues.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Use an indexer cluster to replicate your data.

Forcing a HF to send data to two indexers creates more problems than it solves. Your license will be hit twice. Your searches will return duplicate results. Any failure to connect to indexer (like during maintenance) means your data is no longer in two places. Clustering resolves all of these issues.

---
If this reply helps you, Karma would be appreciated.

jg91
Path Finder

Thank you, I used your solution.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...