CHAPTER 16

image

Scaling and High Availability

All of the examples and projects in the book so far have been based on using a single instance of Splunk, which acts as an indexer and searcher. In this chapter, we will review how to scale Splunk by adding more servers to handle the indexing and search components. You will also learn the basic principles of clustering, which increases the resiliency of Splunk by handling automatic failover of indexers. We will set up a sample cluster to illustrate the basic steps of this process.

Scaling Splunk

The functionality of Splunk can be roughly broken down into three basic areas:

  • Collecting data
  • Indexing the ...

Get Big Data Analytics Using Splunk: Deriving Operational Intelligence from Social Media, Machine Data, Existing Data Warehouses, and Other Real-Time Streaming Sources now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.