Splunk Search

advice for syncing knowledge bundles over the WAN

tpsplunk
Communicator

I have West Coast and an East Coast Datacenters with splunk indexers. my search users are in the West coast so my single search head is here on the West coast. I'd like to use mounted knowledge bundles but i'm not sure its practical to NFS mount my East Coast indexers to a West Coast NFS share. has anyone sync'd knowledge bundles across the country (or further)? should I try the NFS mount or should I do something like create a local NFS mount to East Coast and use a copy process (cron job and rsync job or SAN replication,etc) to copy the knowledge bundle from West Coast to East?

Tags (4)

fbl_itcs
Path Finder

Hi,

I'm having the same issue here. Did you found a practical way to achive this?

Regards,
Felix

0 Karma

tpsplunk
Communicator

No I never got it working. we recently hired someone that had some previous multi-geography splunk experience;we're in the middle of implementing recommended changes. He recommended to only have indexers in your local search environment. In your remote Datacenters configure your universal forwarders to send to locally installed heavy forwarders that do some index level work (transforms,etc). These forward the data on to the indexers in the local DC. obviously this isn't a one size fits all solution. it's probably best to engage splunk professional services to help with this kind of change.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...