Deployment Architecture

How to set up High Availability architecture from my current indexer clustering environment?

logmar5
Explorer

My current Splunk setup is a cluster of 3 indexers, one in each region. One Master, two Peers. With distributed search enabled between them. My next goal is to create High Availability Splunk environment.

If I simply run another duplicate cluster setup on backup servers, that will mean duplicating license cost and storage space.

Does anyone have any suggestions for the proper setup? Or a pointer to a good Splunk doc with details?

Thank you!

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

Yes, we have lots of documentation on this. I suggest that you start with this

http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Aboutclusters

0 Karma
Get Updates on the Splunk Community!

Holistic Visibility and Effective Alerting Across IT and OT Assets

Instead of effective and unified solutions, they’re left with tool fatigue, disjointed alerts and siloed ...

SOC Modernization: How Automation and Splunk SOAR are Shaping the Next-Gen Security ...

Security automation is no longer a luxury but a necessity. Join us to learn how Splunk ES and SOAR empower ...

Ask It, Fix It: Faster Investigations with AI Assistant in Observability Cloud

  Join us in this Tech Talk and learn about the recently launched AI Assistant in Observability Cloud. With ...