Hi @man03359, the design of a clustered Splunk architecture is a job for a Splunk Architect, if you haven't this knowledge or certification, I hint to be supported by a certified one. Anyway, the p...
See more...
Hi @man03359, the design of a clustered Splunk architecture is a job for a Splunk Architect, if you haven't this knowledge or certification, I hint to be supported by a certified one. Anyway, the phases of your job are the following: requisites analysis (users, data volume, apps to use, scheduled searches, perimeter, types of data sources, etc...), design of the architecture, implementation. for the last item, you can see at https://docs.splunk.com/Documentation/Splunk/9.2.1/Indexer/Aboutclusters and https://docs.splunk.com/Documentation/Splunk/9.2.1/DistSearch/AboutSHC For the other two items, a Certified Splunk Architect is mandatory to well design the infrastructure and the architecture. Ciao. Giuseppe