<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Cluster Buckets in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cluster-Buckets/m-p/68061#M2399</link>
    <description>&lt;P&gt;In 6.0, replicated buckets are now kept in the same "level" on both sides.  Hot buckets are replicated into the same location as the hot buckets on the peer.&lt;/P&gt;</description>
    <pubDate>Tue, 20 May 2014 17:22:22 GMT</pubDate>
    <dc:creator>mikelanghorst</dc:creator>
    <dc:date>2014-05-20T17:22:22Z</dc:date>
    <item>
      <title>Splunk Cluster Buckets</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cluster-Buckets/m-p/68057#M2395</link>
      <description>&lt;P&gt;I understand that the hot/warm/cold buckets need the same same storage characteristics for performance. However, is there an in between bucket for data that has aged out but that I would like to retain in slower cheaper disks? &lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2013 02:18:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cluster-Buckets/m-p/68057#M2395</guid>
      <dc:creator>adrianathome</dc:creator>
      <dc:date>2013-06-19T02:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cluster Buckets</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cluster-Buckets/m-p/68058#M2396</link>
      <description>&lt;P&gt;From my perspective it will all depend on your configuration and requirements, however I put the cold bucket on a lower performance tier knowing that search times "could" be impacted since disk IO wouldn't be the same as that serving the hot/warm buckets.&lt;/P&gt;

&lt;P&gt;I optimize the hot bucket for read and write IO, and the warm and cold buckets for read (array side read caches can help dramatically here).  In my opinion it isn't necessarily economical to have cold buckets stored on high-performance storage especially as the data grows to TBs+.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2013 02:59:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cluster-Buckets/m-p/68058#M2396</guid>
      <dc:creator>stevenpoitras</dc:creator>
      <dc:date>2013-06-19T02:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cluster Buckets</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cluster-Buckets/m-p/68059#M2397</link>
      <description>&lt;P&gt;So if your lower tier storage is optimized for reads, how does the replication affect the performance of the cluster? From what I understand the replication is write intensive and it happens on the cold bucket.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2013 03:05:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cluster-Buckets/m-p/68059#M2397</guid>
      <dc:creator>adrianathome</dc:creator>
      <dc:date>2013-06-19T03:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cluster Buckets</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cluster-Buckets/m-p/68060#M2398</link>
      <description>&lt;P&gt;Correct, replication will go from the hot bucket on node 1 to the cold bucked on node 2.  &lt;/P&gt;

&lt;P&gt;If the cold bucket is "optimized for reads", there will be some penalty on write performance causing replication times to be increased.  But for cold, spindle count + read caching is optimal for the sequential repl traffic&lt;/P&gt;

&lt;P&gt;In reality what you're really focusing on is the rate at which data can be read from that replica in the case that the originating node fails.&lt;/P&gt;

&lt;P&gt;As always its about finding the correct balance to fit the IO requirements, but replication IO is essentially a secondary operation.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2013 03:13:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cluster-Buckets/m-p/68060#M2398</guid>
      <dc:creator>stevenpoitras</dc:creator>
      <dc:date>2013-06-19T03:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cluster Buckets</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cluster-Buckets/m-p/68061#M2399</link>
      <description>&lt;P&gt;In 6.0, replicated buckets are now kept in the same "level" on both sides.  Hot buckets are replicated into the same location as the hot buckets on the peer.&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2014 17:22:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cluster-Buckets/m-p/68061#M2399</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2014-05-20T17:22:22Z</dc:date>
    </item>
  </channel>
</rss>

