Splunk SOAR

Restoring From Backup w Warm Standby Question

catherinelam
Explorer

My environment contains two EC2s: one primary and one warm standby. Due to a series of unfortunate events, our database on the warm standby got corrupted and phantom would not start on it. Luckily, we had a volume backup in AWS of the SOAR directory, so it was saved. 

However, after some research afterwards, we found a different method of backing up: https://docs.splunk.com/Documentation/SOARonprem/6.2.2/Admin/BackupOrRestoreAndWarmStandby

I think I'm being dense and overthinking it, but the article mentions a "primary warm standby", a "primary" + a "secondary" + a "warm standby" later on in the article. How many servers are in this configuration? I am not understanding how it is being set up and what the secondary is referencing. Also, what is a "primary warm standby"?

Would this article be helpful in the situation I described above with my failed warm standby? 

Labels (1)
Tags (2)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@catherinelam 

A warm standby is only ever 2 servers, 1 Parent & 1 Child. The Parent syncronises to the Child via postgres sync and rsync for shared files. The failover is still manual but can be scripted if you have the right probe setup on the LB to check and alert when the primary becomes unavailable. 

Personally I think using AWS functionality to restore will give you a quicker time to recovery.

View solution in original post

phanTom
SplunkTrust
SplunkTrust

@catherinelam 

A warm standby is only ever 2 servers, 1 Parent & 1 Child. The Parent syncronises to the Child via postgres sync and rsync for shared files. The failover is still manual but can be scripted if you have the right probe setup on the LB to check and alert when the primary becomes unavailable. 

Personally I think using AWS functionality to restore will give you a quicker time to recovery.

catherinelam
Explorer

Could you clarify what the documentation meant when it said "secondary" and "warm standby primary", if a warm standby only has two servers? I am curious. 

Just wanted to consider my options for backups and present them. 🙂 

0 Karma

phanTom
SplunkTrust
SplunkTrust

@catherinelam "warm standby" is the architecture and Primary / Secondary is the server role. One is only active at any one time. 

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...