Deployment Architecture

Search heads HA

rajkumarv
Engager

Hi,

As per our design, we are planing to deploy 3 indexers in cluster and 2 search heads in HA. Can any one provide the detaiiled procedure on how to setup search heads in High Availability. Also please suggest is there any script available for deploying search head HA.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The closest you'll get to HA search heads is a Search Head Cluster (SHC). SHCs require at least 3 SHs. Note, this is not true HA.

For more about SHCs, see http://docs.splunk.com/Documentation/Splunk/7.2.1/DistSearch/SHCdeploymentoverview.

---
If this reply helps you, Karma would be appreciated.
0 Karma

rajkumarv
Engager

Hi, Thanks. We have only two search heads and will be configured in active and standby using load balancer. Do we have any custom script available to take incremental backups of the configuration and KV store from the primary node and replicated to standby?. Please advice.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Any publicly-available scripts would not be custom. You'll probably have to create your own. The ConfigurationSync app (https://splunkbase.splunk.com/app/574/) is very outdated, but may give you some hints.

To back up the KV Store, try the Gemini KV Store Tools app at https://splunkbase.splunk.com/app/3536/.

---
If this reply helps you, Karma would be appreciated.
0 Karma

rajkumarv
Engager

Thanks Richgalloway. As per the design we have only two search heads and want to be in active and passive. Can we use load balancer to meet the requirement of active and passive?. Also these Splunk instances will be deployed in Windows platform. So can I use Windows based load balancer?.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I believe load balancers expect both sides to be available, but perhaps yours can be configured otherwise.

I'm not familiar with Windows-based LBs.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...