Deployment Architecture

How to achieve The High availability and Disaster recovery architecture in Splunk distributed environment.

Gk7
Engager

Do we have any facility in the Splunk that we can achieve the High availability or Disaster recovery features in the Splunk. if yes, please share the documents for this. 

Your response will be appreciated.!!!

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Splunk has features that increase availability, but I would not call it an HA product.  Those features are:

1) Multi-site indexer cluster.  See https://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/Multisitearchitecture

2) Search head clustering.  See https://docs.splunk.com/Documentation/Splunk/9.0.5/DistSearch/SHCarchitecture

3) Indexer cluster manager redundancy.  See http://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/CMredundancy

See the Splunk Validated Architectures document (https://www.splunk.com/en_us/pdfs/tech-brief/splunk-validated-architectures.pdf), specifically architecture M4/M14.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Splunk has features that increase availability, but I would not call it an HA product.  Those features are:

1) Multi-site indexer cluster.  See https://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/Multisitearchitecture

2) Search head clustering.  See https://docs.splunk.com/Documentation/Splunk/9.0.5/DistSearch/SHCarchitecture

3) Indexer cluster manager redundancy.  See http://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/CMredundancy

See the Splunk Validated Architectures document (https://www.splunk.com/en_us/pdfs/tech-brief/splunk-validated-architectures.pdf), specifically architecture M4/M14.

---
If this reply helps you, Karma would be appreciated.

Gk7
Engager

Ya done now. 

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

As @richgalloway already pointed you could do some kind of HA system with splunk. Indexing tier is real HA with multi site cluster, but SH tier didn’t. With SHC you could get better availability, but you should remember that it’s not designed as a HA!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Hmm. That's interesting.

I don't want to challenge your opinion. I'm just curious as to why you both don't treat SHC as a highly-available solution. I'd say it ticks all the boxes.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...