Deployment Architecture

How to replicate or have a copy of index in two different Splunk Indexer located in different place.

RAVISHANKAR
Loves-to-Learn Lots

Currently I am having a Splunk Indexer with multiple Indexes and a Search Head.


I would like to have one or two indexes to be available in two splunk indexer and data should be available to access from Search Head from both Indexer.


Thanks

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @RAVISHANKAR ,

the best approach is to create an Indexer Cluster that automatically replicate indexes between Indexers, but it requests an additional machine as Cluster Manager, in this way you have HA on your data and you don't pay twice the indexed logs.

Otherwise, you could forward logs to the two Indexers: in this way you pay twice the logs and you don't have HA, but you don't need an additional machine.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

That's something you normally achieve by deploying an indexer cluster.

There is a possibility to migrate a standalone indexer to a clustered setup but it requires some careful planning and is usually best done with help from Professional Services or your friendly local experienced Splunk Partner to work out all the architectural details and plan the whole process.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...