Deployment Architecture

How to set up High Availability architecture from my current indexer clustering environment?

logmar5
Explorer

My current Splunk setup is a cluster of 3 indexers, one in each region. One Master, two Peers. With distributed search enabled between them. My next goal is to create High Availability Splunk environment.

If I simply run another duplicate cluster setup on backup servers, that will mean duplicating license cost and storage space.

Does anyone have any suggestions for the proper setup? Or a pointer to a good Splunk doc with details?

Thank you!

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

Yes, we have lots of documentation on this. I suggest that you start with this

http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Aboutclusters

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...