Splunk IT Service Intelligence

Will the multiple ITSI instances stomp on each others data in common indexes?

archspangler
Path Finder

Is it possible to have multiple ITSI search heads all configured to forward events to a common "Indexer farm"?

-Archie

Tags (2)
0 Karma

DalJeanis
Legend

"Overwrite" isn't usually a thing in Splunk. The more likely issue is that they will both throw data at the same index and it will all get added together. It would be better to make sure that the relevant indexes contained the "region" in the index name.

This is better data management practice anyway, because there are going to be some employees who you want to be able to see the data regarding Dev but not Prod or vice versa, or regarding the various internal customers, and Splunk access controls are primarily at the index level.

An employee should never be able to see any data that they would not have a business need to see, especially if there is PHI (private health information) or PII (personally identifiable information) or company-confidential information involved.

0 Karma

adonio
Ultra Champion

hello there,
i think that the challenge there is to avoid same summary searches ... as you will cause double load on indexers as well as double results in ITSI summary indexes.
what is it that you are trying to achieve?

hope it helps

0 Karma

archspangler
Path Finder

We want to have multiple ITSI instances. (Dev, Prod, other internal customers). All of the data is on our Index cluster; along with the indexes for ITIS. My fear is that all of the ITSI instances would be pointed to the same index cluster and I am afraid that one ITSI instance will overwrite some data the other need.

Unless each ITSI instance is writing it's own unique data into the common indexes.

0 Karma

adonio
Ultra Champion

one way to solve this is to have the Dev ITSI SH index data locally, that will prevent from double indexing in the ITSI summaries on your indexer cluster.
you will still have multiple loads on the indexer layer

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...