Deployment Architecture

Search heads HA

rajkumarv
Engager

Hi,

As per our design, we are planing to deploy 3 indexers in cluster and 2 search heads in HA. Can any one provide the detaiiled procedure on how to setup search heads in High Availability. Also please suggest is there any script available for deploying search head HA.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The closest you'll get to HA search heads is a Search Head Cluster (SHC). SHCs require at least 3 SHs. Note, this is not true HA.

For more about SHCs, see http://docs.splunk.com/Documentation/Splunk/7.2.1/DistSearch/SHCdeploymentoverview.

---
If this reply helps you, Karma would be appreciated.
0 Karma

rajkumarv
Engager

Hi, Thanks. We have only two search heads and will be configured in active and standby using load balancer. Do we have any custom script available to take incremental backups of the configuration and KV store from the primary node and replicated to standby?. Please advice.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Any publicly-available scripts would not be custom. You'll probably have to create your own. The ConfigurationSync app (https://splunkbase.splunk.com/app/574/) is very outdated, but may give you some hints.

To back up the KV Store, try the Gemini KV Store Tools app at https://splunkbase.splunk.com/app/3536/.

---
If this reply helps you, Karma would be appreciated.
0 Karma

rajkumarv
Engager

Thanks Richgalloway. As per the design we have only two search heads and want to be in active and passive. Can we use load balancer to meet the requirement of active and passive?. Also these Splunk instances will be deployed in Windows platform. So can I use Windows based load balancer?.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I believe load balancers expect both sides to be available, but perhaps yours can be configured otherwise.

I'm not familiar with Windows-based LBs.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...