Deployment Architecture

How to set up High Availability architecture from my current indexer clustering environment?


My current Splunk setup is a cluster of 3 indexers, one in each region. One Master, two Peers. With distributed search enabled between them. My next goal is to create High Availability Splunk environment.

If I simply run another duplicate cluster setup on backup servers, that will mean duplicating license cost and storage space.

Does anyone have any suggestions for the proper setup? Or a pointer to a good Splunk doc with details?

Thank you!

0 Karma

Splunk Employee
Splunk Employee

Yes, we have lots of documentation on this. I suggest that you start with this

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!