Deployment Architecture

one-way Indexer replication

jharmer11
New Member

Hey all,

I'm currently working on setting up splunk which I have done but was asked for a setup that I have not done or attempted before and was curious about any thoughts somone could provide. They are asking me to setup a splunk cluster made up of multiple splunk searchhead/indexer instances. Essentially, we have the master splunk that over sees the whole system, and slave splunks that over see the subsystem. Those individual subsystems splunk data, would need to replicate to the master system splunk but not replicate back. For example:

 

Splunk slave 1 collects logs from its machines, and replicates to master splunk

splunk slave 2 collects logs from its machines and gets replicated to master splunk

Master splunk gets all this data but none of it gets replicated back so that the slave splunks do not contain one anothers data. The master would be a infrastructure wide instance able to view data across all systems while the slaves can only view its local systems data. Thats why each would have to have their own search head. 

If i point to different indexers, I read it will count twice against the licensing. Replication gets around this but I have not found if you can setup one way replication so that only master splunk gets all the data while the local splunk can only see its own. Everything seems that if i enable replication, slaves would send to master, and master would replicate any difference in data to each one and that defeats the problem of keeping the slaves data separate. 

 

0 Karma

scelikok
SplunkTrust
SplunkTrust

@jharmer11, Splunk replication does not help you, but I can advise you an easier method.

Just add slave site indexers to the master Search Head as search peers. With this setup Master will be able to search all data on master and all slave sites.

 

If this reply helps you an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...