Knowledge Management

Smartstore configuration multisite cluster

raviadapa
Engager

Hi,

I am working on a project for a client to implement Splunk as a primary logging platform. I have designed the solution to use a multisite cluster across two aws regions. I am struggling to get how i can deploy smartstore in the two regions, which basically will have ind in region A connect to smartstore and ind in region B conn to smartstore in region B. Can you provide an example of this type of configuration.

Regards

Ravi

Labels (1)
0 Karma
1 Solution

raviadapa
Engager

Hi, Thx for the response. I am talking about a multisite cluster stretched two regions. This is a single cluster across two regions.

0 Karma

raviadapa
Engager

Hi Richgalloway,

Thx for the reply. I will read see the recommended solutions below.

Regards

Ravi

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It sounds like you want the indexer clusters to share a SmartStore.  Don't.  Each cluster should have it's own, separate S2 .

---
If this reply helps you, Karma would be appreciated.
0 Karma

srajarat2
Path Finder

Isn't it what a multi-site smartstore should have, a single smartstore shared by the indexers from two sites that are part of the same cluster?  

Also if they are part of the same cluster, wouldn't Cluster Manager push the indexes.conf across all sites which means, the remote volume details has to be the same across the indexers on each site (like the endpoint, bucket name, credentials)?

0 Karma
Get Updates on the Splunk Community!

Customer Experience | Splunk 2024: New Onboarding Resources

In 2023, we were routinely reminded that the digital world is ever-evolving and susceptible to new ...

Celebrate CX Day with Splunk: Take our interactive quiz, join our LinkedIn Live ...

Today and every day, Splunk celebrates the importance of customer experience throughout our product, ...

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...