Deployment Architecture

Search head clustering with multisite indexing cluster - What happens when main site goes down?

jofe
Explorer

Hi,

I'm designing a new Splunk solution based on Search head clustering on top of a multi site indexing cluster. (a small cluster that can grow)

Three search heads (search head cluster), four indexers, two sites. (2 site cluster)

Main data center : Two search heads and two indexers.
Remote data center : One search head and two indexers.

Master node and deployer is located on a VM in main site (can be moved to other site)

Search head config:
replication_factor=3 (all search heads should have complete set)
..
Index cluster config on master node.
[clustering]
mode = master
multisite=true
available_sites=site1,site2
site_replication_factor = origin:1,total:2 (Only one complete copy per data center)
site_search_factor = origin:1,total:2

Q1: Will this work, and is this a good idea? 😉
Q2: If main data center fails, will data still be searchable on remote site even if this search head can't be elected captain?
Q3: If this doesn't work, What must be done to the remote site to make it operational?

Thanks!

1 Solution

matthieu_araman
Communicator

I think it will work in the following mode
adhoc search (classic) OK
scheduled : disabled because no captain

but scheduling may be very important (and there are stuff done in the background which are scheduled)

I would certainly go for 2 SH on each site
It's active-active so takes this into account for sizing (it could be on a vm in some cases)

View solution in original post

0 Karma

matthieu_araman
Communicator

I think it will work in the following mode
adhoc search (classic) OK
scheduled : disabled because no captain

but scheduling may be very important (and there are stuff done in the background which are scheduled)

I would certainly go for 2 SH on each site
It's active-active so takes this into account for sizing (it could be on a vm in some cases)

0 Karma

mikaelbje
Motivator

Surprised you haven't received an official answer here. This is of great interest to a lot of folks. Did you figure out a working setup?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...