Deployment Architecture

How to achieve The High availability and Disaster recovery architecture in Splunk distributed environment.

Gk7
Engager

Do we have any facility in the Splunk that we can achieve the High availability or Disaster recovery features in the Splunk. if yes, please share the documents for this. 

Your response will be appreciated.!!!

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Splunk has features that increase availability, but I would not call it an HA product.  Those features are:

1) Multi-site indexer cluster.  See https://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/Multisitearchitecture

2) Search head clustering.  See https://docs.splunk.com/Documentation/Splunk/9.0.5/DistSearch/SHCarchitecture

3) Indexer cluster manager redundancy.  See http://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/CMredundancy

See the Splunk Validated Architectures document (https://www.splunk.com/en_us/pdfs/tech-brief/splunk-validated-architectures.pdf), specifically architecture M4/M14.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Splunk has features that increase availability, but I would not call it an HA product.  Those features are:

1) Multi-site indexer cluster.  See https://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/Multisitearchitecture

2) Search head clustering.  See https://docs.splunk.com/Documentation/Splunk/9.0.5/DistSearch/SHCarchitecture

3) Indexer cluster manager redundancy.  See http://docs.splunk.com/Documentation/Splunk/9.0.5/Indexer/CMredundancy

See the Splunk Validated Architectures document (https://www.splunk.com/en_us/pdfs/tech-brief/splunk-validated-architectures.pdf), specifically architecture M4/M14.

---
If this reply helps you, Karma would be appreciated.

Gk7
Engager

Ya done now. 

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

As @richgalloway already pointed you could do some kind of HA system with splunk. Indexing tier is real HA with multi site cluster, but SH tier didn’t. With SHC you could get better availability, but you should remember that it’s not designed as a HA!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Hmm. That's interesting.

I don't want to challenge your opinion. I'm just curious as to why you both don't treat SHC as a highly-available solution. I'd say it ticks all the boxes.

0 Karma
Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...