Splunk Enterprise Security

Splunk enterprise and Enterprise Security High availability

hariskhan
Explorer

Hi all,
I have a single splunk server machine running splunk enterprise 7. How can i create high availability solution for this.
Also how can i be able to ensure Splunk ES high availability if i have two Splunk enterprise server instances?.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

A single-instance Splunk server cannot be HA. For Splunk to be highly available, you need multi-site search head and indexer clusters. Even that isn't perfect as the loss of a site may mean the search heads can't elect a new captain (among other possible problems).

Some have come up with other answers using various vmWare or cloud features.

I think HA is not supported for Enterprise Security.

---
If this reply helps you, Karma would be appreciated.

hariskhan
Explorer

So technically we cannot ensure high availability for Splunk enterprise or Enterprise security until we do clustering for Index and SH right?.

How about if we use shared storage that is available to primary Splunk instance and when that primary goes down we unmount the SAN storage from primary instance and then mount same storage to secondary instance?.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Even clustering won't be enough to make Enterprise Security HA. It is highly dependent on the KV Store, which be backed up regularly. Any secondary instance's recovery point will be determined by the most recent backup.

Shared storage can be made to work, but serves to reduce recovery time rather than be a true HA solution. Make sure the SAN's I/O rate is high enough to keep up with Splunk.

---
If this reply helps you, Karma would be appreciated.
0 Karma

hariskhan
Explorer

Thanks Sir,
Helped a lot.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...