<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Distributed Deployment: Splunk data replication in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Deployment-Splunk-data-replication/m-p/56084#M1859</link>
    <description>&lt;P&gt;You are correct that if one indexer is out, only half the data will be visible, though the search head will report that it is unable to reach all indexers.&lt;/P&gt;

&lt;P&gt;In the current version, there is no native replication of data. You will have to do this either using the underlying storage to replicate, or by forwarding from indexer to a replica instance. Both have disadvantages relative to the other. In addition, there is no built-in mechanism for failover, so you would have to implement this yourself. These solutions are not entirely simple to implement correctly and robustly. An overview of this is here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.2/Installation/Highavailabilityreferencearchitecture"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.2/Installation/Highavailabilityreferencearchitecture&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In future versions, you may expect some form of built-in replication, as well as a more automated built-in failover, that should be preferable to these other methods.&lt;/P&gt;</description>
    <pubDate>Sat, 19 May 2012 17:13:46 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2012-05-19T17:13:46Z</dc:date>
    <item>
      <title>Distributed Deployment: Splunk data replication</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Deployment-Splunk-data-replication/m-p/56083#M1858</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I have a question with a distributed deployment...&lt;/P&gt;

&lt;P&gt;If a deployment was set-up to have for example:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;2 x Indexers&lt;/LI&gt;
&lt;LI&gt;n x Forwarders (set-up to autoLb between the indexers)&lt;/LI&gt;
&lt;LI&gt;1 x Search Head&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The autoLB will forward data to the Splunk indexers in a cycle based on time.What happens to the visibility of data if one of the Indexers was to become inactive (e.g. a system failure, etc). I would imagine that Splunk would be able to view ~half of the data, is this assumption correct?&lt;/P&gt;

&lt;P&gt;How would data replication between the Indexers take place? - If the there is a requirement for the data to remain 100% visible, what would be best to achieve this? &lt;/P&gt;

&lt;P&gt;I'm sure I have come across guidelines on data replication between two indexers in past notes/discussions/Splunk documentation. But I am not able to find the justification I require.&lt;/P&gt;

&lt;P&gt;Are there any thoughts on documentation or sources of information that would be useful?&lt;/P&gt;

&lt;P&gt;Any thoughts welcome, thanks in advance.&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;MHibbin&lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2012 16:37:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Deployment-Splunk-data-replication/m-p/56083#M1858</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-05-19T16:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Deployment: Splunk data replication</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Deployment-Splunk-data-replication/m-p/56084#M1859</link>
      <description>&lt;P&gt;You are correct that if one indexer is out, only half the data will be visible, though the search head will report that it is unable to reach all indexers.&lt;/P&gt;

&lt;P&gt;In the current version, there is no native replication of data. You will have to do this either using the underlying storage to replicate, or by forwarding from indexer to a replica instance. Both have disadvantages relative to the other. In addition, there is no built-in mechanism for failover, so you would have to implement this yourself. These solutions are not entirely simple to implement correctly and robustly. An overview of this is here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.2/Installation/Highavailabilityreferencearchitecture"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.2/Installation/Highavailabilityreferencearchitecture&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In future versions, you may expect some form of built-in replication, as well as a more automated built-in failover, that should be preferable to these other methods.&lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2012 17:13:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Deployment-Splunk-data-replication/m-p/56084#M1859</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-05-19T17:13:46Z</dc:date>
    </item>
  </channel>
</rss>

