Hi,
I'm hoping someone can help me to understand if the following is possible with Splunk Enterprise as I'm just learning about the various components for a design I'm writing.
The environment I'm working with will have around 100 Windows VMs initially, growing to 200+, probably across a few domains. There will also be networking devices to support that infrastructure which we want to be able to collect logs from as well.
We are going to have two sites (active / passive) and I have two virtual servers in each site assigned to Splunk, although the DR site will be a standby. I'm trying to work with these two VMs without requesting more, although it may be possible to add more.
From what I've read, I think I would be looking at a Data Consolidation topology i.e. multiple universal forwarders pushing data to an indexer / search server. If I wanted to consider high availability options within a single site, I might want to cluster the indexers, but as I only have two servers I'm wondering if it's possible to create a two node cluster hosting both the search and indexing roles?
I don't think this is possible, as under the 'Cluster Nodes' guidance, it states that "Master nodes, peer nodes, and search heads are all specialized Splunk Enterprise instances. All nodes must reside on separate instances and separate machines." - this looks to me like I wouldn't be able to have a cluster with just two servers regardless.
The other option I'm looking at would be to have one server as an Indexer and one as a search / indexer. Forwarders could then get data into the Indexers from the 100+ VMs.
We do have DR options available and will be backing up, so high availability is not necessarily required and could be added later with increased demand.
I suppose the questions are;
1) Is a clustering solution possible with two servers, or what would the minimum number of servers be? Could it be done with 3; two indexers and one search head, or would I need to have a seperate Master Node as well?
2) Am I right in thinking that if I had one server as an Indexer and one as an Indexer / search server, if the dedicated Indexer went down, the results would be incomplete? Furthermore, if the search server went down search would therefore be totally unavaiiable?
3) Is it possible to have two servers running as both Indexers and Search servers, or would I need a search head to manage both indexers in this case?
Many thanks!
M
... View more