Deployment Architecture

How to configure the splunk on two servers ?

sunrise
Contributor

Hi Splunkers,

I'm considering about splunk system on two servers.

What type of architectures can you think ?

Requirements for this system are followings.

  • No data duplications
  • Need to redundancy for application and hardware issues
  • One server is primary, another secondary (Generally Active-Stanby configuration)

We'll get data into Splunk with NFS mount of syslog server on splunk server.
Thank you for your help.

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Splunk's way of creating redundancy between indexers is clustering: http://docs.splunk.com/Documentation/Splunk/6.1.1/Indexer/Aboutclusters

For redundancy between search heads Splunk comes with search head pooling: http://docs.splunk.com/Documentation/Splunk/6.1.1/DistSearch/Configuresearchheadpooling

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Splunk's way of creating redundancy between indexers is clustering: http://docs.splunk.com/Documentation/Splunk/6.1.1/Indexer/Aboutclusters

For redundancy between search heads Splunk comes with search head pooling: http://docs.splunk.com/Documentation/Splunk/6.1.1/DistSearch/Configuresearchheadpooling

sunrise
Contributor

Thank you, martin_mueller.
But splunk clustering needs more than 3 servers(IDX*3, SH*2, Master)....

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...