Deployment Architecture

How to configure the splunk on two servers ?

sunrise
Contributor

Hi Splunkers,

I'm considering about splunk system on two servers.

What type of architectures can you think ?

Requirements for this system are followings.

  • No data duplications
  • Need to redundancy for application and hardware issues
  • One server is primary, another secondary (Generally Active-Stanby configuration)

We'll get data into Splunk with NFS mount of syslog server on splunk server.
Thank you for your help.

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Splunk's way of creating redundancy between indexers is clustering: http://docs.splunk.com/Documentation/Splunk/6.1.1/Indexer/Aboutclusters

For redundancy between search heads Splunk comes with search head pooling: http://docs.splunk.com/Documentation/Splunk/6.1.1/DistSearch/Configuresearchheadpooling

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Splunk's way of creating redundancy between indexers is clustering: http://docs.splunk.com/Documentation/Splunk/6.1.1/Indexer/Aboutclusters

For redundancy between search heads Splunk comes with search head pooling: http://docs.splunk.com/Documentation/Splunk/6.1.1/DistSearch/Configuresearchheadpooling

sunrise
Contributor

Thank you, martin_mueller.
But splunk clustering needs more than 3 servers(IDX*3, SH*2, Master)....

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...