Splunk Search

Small Setup DR

mbalzarini
New Member

We have a very small install of a single Splunk 6.01 server. We are required to have DR capability for all of our production servers and I wanted to see what the best way to do this. Would the reccomended route be to setup a Forwarder from our Prod server to the DR server and run with the "indexAndForward = true" setting? Thank you for your assistance.

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

There are several approaches, depending on what you need in which disaster scenario.

Your idea should work for mirroring data that arrives at your prod server while it is available, but what happens once the prod server dies? It loses its data, no problem - that was mirrored to the DR server... but now the DR server stops getting data because the prod server is gone. Whether that's a problem for you or not depends on your risk management requirements.

As an alternative, you can configure your forwarders to clone the data to prod and DR, so even when the prod server dies the DR server is still getting data.

As another alternative, you can set up a small Splunk cluster. That won't impact your license, but only protect against small-scale failures of single machines - not against a major datacenter disaster.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

There are several approaches, depending on what you need in which disaster scenario.

Your idea should work for mirroring data that arrives at your prod server while it is available, but what happens once the prod server dies? It loses its data, no problem - that was mirrored to the DR server... but now the DR server stops getting data because the prod server is gone. Whether that's a problem for you or not depends on your risk management requirements.

As an alternative, you can configure your forwarders to clone the data to prod and DR, so even when the prod server dies the DR server is still getting data.

As another alternative, you can set up a small Splunk cluster. That won't impact your license, but only protect against small-scale failures of single machines - not against a major datacenter disaster.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...