Deployment Architecture

How can I configure indexes to replicate data with each other in a Splunk deployment?

rashid47010
Communicator

Hi everyone
I am planning to create a Splunk lab.
I want
2 Forwarders- who will receive the logs from multiple sources(windows, UNIX, log files, etc)
2 indexers who are you replicating data with each other

One search head.

For forwards high availability I configure both indexers IP’s in output.conf file in both Forwarders.

Q-Now how can I configure indexes to replicate data with each other?

0 Karma
1 Solution

adonio
Ultra Champion

@rashid47010,
please refer to above comments by @SteveG and @skoelpin
for an indexer cluster to replicate data you will need at least 4 machines - 1 Cluster Master, 1 Search Head and 2 Indexers.

hope it helps

View solution in original post

adonio
Ultra Champion

@rashid47010,
please refer to above comments by @SteveG and @skoelpin
for an indexer cluster to replicate data you will need at least 4 machines - 1 Cluster Master, 1 Search Head and 2 Indexers.

hope it helps

ssadanala1
Contributor

Hi

Configure your SH to search thru both indexers.

Thats will be the best shot for dev . environment

rashid47010
Communicator

how can I accept your answer

0 Karma

rashid47010
Communicator

@ssadanala1
thanks.
it is helpful to understand basic concept.

0 Karma

ssadanala1
Contributor

Hi,

You can configure your SH to search through both indexers .

That will be the best shot in this scenario

0 Karma

p_gurav
Champion

you can configure indexer clustering. Refer below docs:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Indexer/Aboutclusters

0 Karma

rashid47010
Communicator

hi
thanks for your kind reply.
I believe that I need another server as index cluster.
I am limited with resources.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Don't cluster your indexers until you have 3 indexers and 1 cluster master available

0 Karma

p_gurav
Champion

This is not best practice, but you can make your search head as cluster master and then configure indexer clustering, as you have limited resources.

0 Karma

Steve_G_
Splunk Employee
Splunk Employee

More than "not best practice", using a search head as the cluster master is not supported. See http://docs.splunk.com/Documentation/Splunk/7.0.3/Indexer/Systemrequirements#Required_Splunk_Enterpr...

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...