Deployment Architecture

Multi-Site Search Head Clustering

jwalrath1
Explorer

I understand that there are 2 approved architectures for multi site search head clustering. One, where each site has their own independent search head clustering that has search affinity with index clusters, and a second option where there is a search head cluster stretched across the two sites.

For the first option where the search head clusters are independent to each site, I have read that search head clusters are not site-aware. Does this mean that things saved through the search head cluster on site 1 would not replicate to site 2? For example, if I were to create a new dashboard at site 1 on the web UI through the search head cluster, that would not replicate to site 2?

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You are correct.  In the first architecture, the two SHCs are independent and unaware of each other.  Independent clusters do not share/replicate KOs  with/to each other.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

jwalrath1
Explorer

Thanks @richgalloway I have a second part to this question. Can I use the manager node to do a deployment to replicate configurations (dashboards and reports) saved on  site A to site B? Could this be done with the SHC deployer if I were to do a deployment on a weekly bases for example?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You are correct.  In the first architecture, the two SHCs are independent and unaware of each other.  Independent clusters do not share/replicate KOs  with/to each other.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...