Do we have any facility in the Splunk that we can achieve the High availability or Disaster recovery features in the Splunk. if yes, please share the documents for this.
Your response will be appreciated.!!!
Splunk has features that increase availability, but I would not call it an HA product. Those features are:
1) Multi-site indexer cluster. See https://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/Multisitearchitecture
2) Search head clustering. See https://docs.splunk.com/Documentation/Splunk/9.0.5/DistSearch/SHCarchitecture
3) Indexer cluster manager redundancy. See http://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/CMredundancy
See the Splunk Validated Architectures document (https://www.splunk.com/en_us/pdfs/tech-brief/splunk-validated-architectures.pdf), specifically architecture M4/M14.
Splunk has features that increase availability, but I would not call it an HA product. Those features are:
1) Multi-site indexer cluster. See https://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/Multisitearchitecture
2) Search head clustering. See https://docs.splunk.com/Documentation/Splunk/9.0.5/DistSearch/SHCarchitecture
3) Indexer cluster manager redundancy. See http://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/CMredundancy
See the Splunk Validated Architectures document (https://www.splunk.com/en_us/pdfs/tech-brief/splunk-validated-architectures.pdf), specifically architecture M4/M14.
As @richgalloway already pointed you could do some kind of HA system with splunk. Indexing tier is real HA with multi site cluster, but SH tier didn’t. With SHC you could get better availability, but you should remember that it’s not designed as a HA!
Hmm. That's interesting.
I don't want to challenge your opinion. I'm just curious as to why you both don't treat SHC as a highly-available solution. I'd say it ticks all the boxes.