Splunk Search

advice for syncing knowledge bundles over the WAN

tpsplunk
Communicator

I have West Coast and an East Coast Datacenters with splunk indexers. my search users are in the West coast so my single search head is here on the West coast. I'd like to use mounted knowledge bundles but i'm not sure its practical to NFS mount my East Coast indexers to a West Coast NFS share. has anyone sync'd knowledge bundles across the country (or further)? should I try the NFS mount or should I do something like create a local NFS mount to East Coast and use a copy process (cron job and rsync job or SAN replication,etc) to copy the knowledge bundle from West Coast to East?

Tags (4)

fbl_itcs
Path Finder

Hi,

I'm having the same issue here. Did you found a practical way to achive this?

Regards,
Felix

0 Karma

tpsplunk
Communicator

No I never got it working. we recently hired someone that had some previous multi-geography splunk experience;we're in the middle of implementing recommended changes. He recommended to only have indexers in your local search environment. In your remote Datacenters configure your universal forwarders to send to locally installed heavy forwarders that do some index level work (transforms,etc). These forward the data on to the indexers in the local DC. obviously this isn't a one size fits all solution. it's probably best to engage splunk professional services to help with this kind of change.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...