Deployment Architecture

one-way Indexer replication

jharmer11
New Member

Hey all,

I'm currently working on setting up splunk which I have done but was asked for a setup that I have not done or attempted before and was curious about any thoughts somone could provide. They are asking me to setup a splunk cluster made up of multiple splunk searchhead/indexer instances. Essentially, we have the master splunk that over sees the whole system, and slave splunks that over see the subsystem. Those individual subsystems splunk data, would need to replicate to the master system splunk but not replicate back. For example:

 

Splunk slave 1 collects logs from its machines, and replicates to master splunk

splunk slave 2 collects logs from its machines and gets replicated to master splunk

Master splunk gets all this data but none of it gets replicated back so that the slave splunks do not contain one anothers data. The master would be a infrastructure wide instance able to view data across all systems while the slaves can only view its local systems data. Thats why each would have to have their own search head. 

If i point to different indexers, I read it will count twice against the licensing. Replication gets around this but I have not found if you can setup one way replication so that only master splunk gets all the data while the local splunk can only see its own. Everything seems that if i enable replication, slaves would send to master, and master would replicate any difference in data to each one and that defeats the problem of keeping the slaves data separate. 

 

0 Karma

scelikok
SplunkTrust
SplunkTrust

@jharmer11, Splunk replication does not help you, but I can advise you an easier method.

Just add slave site indexers to the master Search Head as search peers. With this setup Master will be able to search all data on master and all slave sites.

 

If this reply helps you an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...