Any Splunk gurus out there? I'm new to the product, but have been asked to look over a proposed architecture. As I'm reading through the documentation I've read about "clusters". The guy that put together the architecture for us, says we don't need a cluster. That all of the HA and fail over capabilities are built in. To me that didn't seem right, considering how much their documentation talks about clustering. Initial config is to include:
(2) Search heads (7) Indexers (1) deployment server So the question is don't we need a cluster for HA? Christopher Bodnar Enterprise Architect I, Corporate Office of Technology:Enterprise Architecture and Engineering Services Tel 610-807-6459 3900 Burgess Place, Bethlehem, PA 18017 [email protected] The Guardian Life Insurance Company of America www.guardianlife.com ----------------------------------------- This message, and any attachments to it, may contain information that is privileged, confidential, and exempt from disclosure under applicable law. If the reader of this message is not the intended recipient, you are notified that any use, dissemination, distribution, copying, or communication of this message is strictly prohibited. If you have received this message in error, please notify the sender immediately by return e-mail and delete the message and any attachments. Thank you.

