Deployment Architecture

Multisite deployment with indexers and search heads on the same machine

laithmurad
Path Finder

Initially we were going to go with a standalone single Splunk server, but we have a requirement for a DR strategy, and the multisite cluster seems like the best way to go.

We're going to be provisioning 3 windows servers to achieve this, which would be functioning like this:

1 server for cluster master in site A.

1 server acting like an indexer peer and a search head in site A.

1 server acting like an indexer peer and a search head in site B.

I'm combining the search head and the indexer functionality within the same server because we don't have huge amount of data to index, and we will not be performing searches constantly.

Do we need to install 2 instances of Splunk in each server? One instance as a search head and another one as an indexer? Or can I achieve this with a single Splunk instance(installation) in each server?

Thanks.

0 Karma
1 Solution

mahamed_splunk
Splunk Employee
Splunk Employee

You would require 2 instances (one for indexer, and one for search head).

View solution in original post

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

You would require 2 instances (one for indexer, and one for search head).

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...