Monitoring Splunk

Using one instance of splunk to monitor aws and azure

celticwarrior73
New Member

Hi,

Is it possible to use one instance of Splunk to monitor two cloud vendor environments? As in an AWS and an Azure, and what would the architecture look like? Also, are there any downsides to doing this?

Thanks,

Anthony

Tags (1)
0 Karma

richkappler
Path Finder

I would suggest, for your own sanity, setting up an indexer cluster and having AWS as one site and Azure as another, but monitoring both environments from one Splunk instance is easily achieved.

0 Karma

FrankVl
Ultra Champion

Why exactly would you recommend that? It means managing two different types of infrastructure, also different instance types and all. I would say it is much easier to manage a Splunk cluster that is fully built on either AWS or Azure, not split across both?

I can imagine it might be a bit easier if you can point Azure sources to the Azure indexer site and AWS sources to the AWS indexer site, but wondering if that advantage outweighs the disadvantages of having such a split set up?

If you do so: do make sure latency between those 2 environments is within acceptable limits. https://answers.splunk.com/answers/317146/what-is-the-maximum-latency-we-should-see-between.html mentions 100ms as a guideline.

0 Karma

celticwarrior73
New Member

My thoughts are around scale, as we could go with a number of cloud offerings over many tiers which we could then end up running loads of different splunk instances.. so I am concerned from an analysis point of view where we could end of with loads of screens to watch. and yes we would have indexers in both site environments to keep that continuity.

0 Karma

FrankVl
Ultra Champion

As long as you can arrange connectivity from each of those environments to your Splunk environment: sure.

Enabling connectivity from a certain cloud environment to somewhere else might be a bit more difficult than arranging connectivity within the environment, but technically there is no reason why you couldn't send logs from AWS hosted devices and from Azure hosted systems to a single Splunk environment.

0 Karma

celticwarrior73
New Member

Thank you for your answer, that is very helpful.

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...