Splunk Enterprise Security

Has any great person here written a Back up / DR for Splunk ES? Any guidance is much appreciated.

SamHTexas
Builder

I have Indexer clustering, SH clustering in a distributed environment. 

Labels (1)
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

For the ES portion of things, also consider this:
https://docs.splunk.com/Documentation/ES/6.6.0/Install/InstallEnterpriseSecuritySHC#Back_up_and_rest... 

Let me know if that helps. 

0 Karma

codebuilder
Influencer

This is a complex topic and you should really engage Splunk support for guidance on how to implement these strategies.

With that said, one option for DR is to implement multi-site clustering.

https://docs.splunk.com/Documentation/Splunk/8.2.1/Indexer/Multisitearchitecture

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...