Deployment Architecture

How to set up High Availability architecture from my current indexer clustering environment?

logmar5
Explorer

My current Splunk setup is a cluster of 3 indexers, one in each region. One Master, two Peers. With distributed search enabled between them. My next goal is to create High Availability Splunk environment.

If I simply run another duplicate cluster setup on backup servers, that will mean duplicating license cost and storage space.

Does anyone have any suggestions for the proper setup? Or a pointer to a good Splunk doc with details?

Thank you!

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

Yes, we have lots of documentation on this. I suggest that you start with this

http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Aboutclusters

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...