Splunk Enterprise Security

Disaster Recovery for ES SH cluster Enviornment

vinayakwagh
Explorer

what is the solution for DR where ES app is in Sh cluster?

0 Karma

DavidHourani
Super Champion

Hi @vinayakwagh,

I'm guessing you already know the difference between DR and HA for asking this question.

If you are looking for a DR solution for ES and you're already in stand-alone mode, then a backup of Splunk configuration including ES apps, ad-ons and the kv-store are enough. No need to setup a SH-Cluster, it will only complicate things.

If you're actually looking for HA, then SH clustering could be the solution for you, have a look here for the list of benefits of an SH-cluster:
https://docs.splunk.com/Documentation/Splunk/7.3.0/DistSearch/AboutSHC#Benefits_of_a_search_head_clu...

Cheers,
David

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...