Deployment Architecture

Multiple indexer clusters environment

omerl
Path Finder

Hey,
I am thinking of having 2 indexer clusters in my environment:
1. “Raw data” cluster, which receives data from windows event forwarders & other “external” connectors.
2. Summary cluster, which receives data from search heads, after those summarized it and took out only part of the “raw data” from cluster 1.

I was wondered whether this is the best solution to my problem, as I want to summarize the data to keep it searchable, which is not possible with the amounts of raw data I have, but still let the users use the “raw data” on real time, so both clusters are needed to be searched.

Is separating the clusters a good idea? Maybe it would be better to use 1 cluster for both purposes, using the same hardware?

Thanks!

0 Karma
1 Solution

xpac
SplunkTrust
SplunkTrust

So far, I don't see a good reason for separating those indexers.
They can share the load more evenly when sharing all work, so I'd keep them all together.

Hope that helps.

View solution in original post

0 Karma

xpac
SplunkTrust
SplunkTrust

So far, I don't see a good reason for separating those indexers.
They can share the load more evenly when sharing all work, so I'd keep them all together.

Hope that helps.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...