Deployment Architecture

How to achieve The High availability and Disaster recovery architecture in Splunk distributed environment.

Gk7
Engager

Do we have any facility in the Splunk that we can achieve the High availability or Disaster recovery features in the Splunk. if yes, please share the documents for this. 

Your response will be appreciated.!!!

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Splunk has features that increase availability, but I would not call it an HA product.  Those features are:

1) Multi-site indexer cluster.  See https://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/Multisitearchitecture

2) Search head clustering.  See https://docs.splunk.com/Documentation/Splunk/9.0.5/DistSearch/SHCarchitecture

3) Indexer cluster manager redundancy.  See http://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/CMredundancy

See the Splunk Validated Architectures document (https://www.splunk.com/en_us/pdfs/tech-brief/splunk-validated-architectures.pdf), specifically architecture M4/M14.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Splunk has features that increase availability, but I would not call it an HA product.  Those features are:

1) Multi-site indexer cluster.  See https://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/Multisitearchitecture

2) Search head clustering.  See https://docs.splunk.com/Documentation/Splunk/9.0.5/DistSearch/SHCarchitecture

3) Indexer cluster manager redundancy.  See http://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/CMredundancy

See the Splunk Validated Architectures document (https://www.splunk.com/en_us/pdfs/tech-brief/splunk-validated-architectures.pdf), specifically architecture M4/M14.

---
If this reply helps you, Karma would be appreciated.

Gk7
Engager

Ya done now. 

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

As @richgalloway already pointed you could do some kind of HA system with splunk. Indexing tier is real HA with multi site cluster, but SH tier didn’t. With SHC you could get better availability, but you should remember that it’s not designed as a HA!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Hmm. That's interesting.

I don't want to challenge your opinion. I'm just curious as to why you both don't treat SHC as a highly-available solution. I'd say it ticks all the boxes.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...