Hi all,
We have two sites NBB4 and NBB2. We would like to install two splunk, one in each site. The Splunk server located in NBB2 will be the active splunk and will receive all Syslog from appliance located in NBB2 and NBB4. The Splunk server located in NBB4 will be passive.
In case of problem with Splunk in NBB2, we will rename hostname, change ip address and start Splunk on NBB4, he will become the active server.
My question is : is it possible to use rsync to copy splunk db from server NBB2 to server NBB4 ?
Or is it better to use the forwarding fearture of Splunk and work in an active/active configuration ?
But, if I use an active/active configuration and if I use the enterprise version, do I have to pay two licences ?
Thanks.
Regards,
Pierre.