Hi Splunkers,
I'm considering about splunk system on two servers.
What type of architectures can you think ?
Requirements for this system are followings.
We'll get data into Splunk with NFS mount of syslog server on splunk server.
Thank you for your help.
Splunk's way of creating redundancy between indexers is clustering: http://docs.splunk.com/Documentation/Splunk/6.1.1/Indexer/Aboutclusters
For redundancy between search heads Splunk comes with search head pooling: http://docs.splunk.com/Documentation/Splunk/6.1.1/DistSearch/Configuresearchheadpooling
Splunk's way of creating redundancy between indexers is clustering: http://docs.splunk.com/Documentation/Splunk/6.1.1/Indexer/Aboutclusters
For redundancy between search heads Splunk comes with search head pooling: http://docs.splunk.com/Documentation/Splunk/6.1.1/DistSearch/Configuresearchheadpooling
Thank you, martin_mueller.
But splunk clustering needs more than 3 servers(IDX*3, SH*2, Master)....