Hi,
I'm planning on deploying a Splunk infrastructure.
I'm currently undecided whether I should build the infrastructure according to the following configurations.
1 Search Head for each data center (hosted on ESX)
1 Indexer for each datacenter (hosted on ESX)
OR
2 Indexers for each datacenter (hosted on ESX)
With 1 indexer on each site, I planned to have a replication factor of 2 and a search factor of 2 and a site-rep-factor of 1.
With 2 indexers on each site a replication factor of 4 and a search factor of 3 and a site-rep-factor of 2.
Is it advisable to host 2 smaller indexers instead of one big indexer?
Are there performance benefits or caveats?
Regards,
pyro_wood
Multi-site clustering requires at least 2 indexers per site. Both of them must meet Splunk's minimum requirements.
Multi-site clustering requires at least 2 indexers per site. Both of them must meet Splunk's minimum requirements.
Thank you, I didn't take this into consideration
I think you could also have a multi site cluster with one site and one indexer