Deployment Architecture

Single-server Splunk (S1) on windows server 2012 2-node failover cluster - good idea?

yangtse
Explorer

We need a High Availability (HA) Splunk Environment. The ideal architecture would be Distributed Clustered Deployment + SHC - Single Site (C3 / C13), which includes a 2-node Indexer Cluster, 3-node Search Head Cluster, 1 Deployment Server, etc.

But, we only have 2 available servers-virtual machine with Win 2012. So, I'm thinking to build a 2-node Windows Server Failover Cluster, then install a Single Splunk Server (S1) (one instance includes Search Head and Indexer) on this cluster. Is this possible?

I don't have much experience on Splunk architecture. I did research online, seems no one mentioned this solution. Is this a good idea? any Pros and Cons? Any suggestions are welcome. Thank you!

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...