Splunk Search

Splunk HA architecture using SAN

KomalSharma
Explorer

Hello everyone,

I am referring to the HA option using SAN as explained in this document.

http://docs.splunk.com/Documentation/Splunk/latest/Installation/Highavailabilityreferencearchitectur...

I am wondering if anyone has implemented HA using SAN and if so, can you please share your experience?
Reading through older posts it looks like the data replication seems to be the preferred way.
Is there any distinct advantage of one method v/s another? We have just started using Splunk and want to do some analysis before commiting to our production setup.

Thanks,
Komal

Tags (1)

Damien_Dallimor
Ultra Champion

The SAN overview in that link describes an HA scenario by which you remount a single SAN volume onto a failover server instance when a primary server instance goes down.

There is also another SAN architecture that you can use to achieve an HA and DR position whereby you can enable SAN replication to your DR site. This is my preferred approach.

The alternative approach by using Splunk functionality is configuring your Splunk Forwarders to "auto load balance" and "data clone" over your primary and DR Indexer Clusters, which has additional license cost implications.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...