My current Splunk setup is a cluster of 3 indexers, one in each region. One Master, two Peers. With distributed search enabled between them. My next goal is to create High Availability Splunk environment.
If I simply run another duplicate cluster setup on backup servers, that will mean duplicating license cost and storage space.
Does anyone have any suggestions for the proper setup? Or a pointer to a good Splunk doc with details?
Thank you!
Yes, we have lots of documentation on this. I suggest that you start with this
http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Aboutclusters