<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Increasing Replication and Search Factor in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Increasing-Replication-and-Search-Factor/m-p/616624#M26212</link>
    <description>&lt;P&gt;I have 3 Search Heads and 3 Indexers with Replication Factor =1 and Search Factor=1. My requirement is to increase this to RF=3 and SF=2&lt;/P&gt;&lt;P&gt;Each indexer has around 800GB of data.&lt;/P&gt;&lt;P&gt;Now if I increase the replication factor to 3 does it mean each indexer will end up with around 2.4TB of data post data rebalancing.&lt;/P&gt;&lt;P&gt;And what would be the approximate data size in each indexer if RF is set to 2.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Oct 2022 08:31:52 GMT</pubDate>
    <dc:creator>shrutheen</dc:creator>
    <dc:date>2022-10-11T08:31:52Z</dc:date>
    <item>
      <title>Increasing Replication and Search Factor</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Increasing-Replication-and-Search-Factor/m-p/616624#M26212</link>
      <description>&lt;P&gt;I have 3 Search Heads and 3 Indexers with Replication Factor =1 and Search Factor=1. My requirement is to increase this to RF=3 and SF=2&lt;/P&gt;&lt;P&gt;Each indexer has around 800GB of data.&lt;/P&gt;&lt;P&gt;Now if I increase the replication factor to 3 does it mean each indexer will end up with around 2.4TB of data post data rebalancing.&lt;/P&gt;&lt;P&gt;And what would be the approximate data size in each indexer if RF is set to 2.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 08:31:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Increasing-Replication-and-Search-Factor/m-p/616624#M26212</guid>
      <dc:creator>shrutheen</dc:creator>
      <dc:date>2022-10-11T08:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: Increasing Replication and Search Factor</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Increasing-Replication-and-Search-Factor/m-p/616639#M26215</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/89357"&gt;@shrutheen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The question is: I suppose that you have an Indexer Cluster, so why have you RF=1?&lt;/P&gt;&lt;P&gt;Anyway, I think that having 800 GB with RF=1 and SF=1 you shouldn't have 2400 GB with RF=3 and SR=2 because the tsindexes (SF) take around the 35% of the space required, so you should have for 100GB/day:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;total row data = 100GB * 15% * RF = 45GB
tsindexes data = 100GB * 35% * SF = 70GB
total storage = 115GB
peer storage =total / 3 = 38.3GB&lt;/LI-CODE&gt;&lt;P&gt;So what's the daily indexed logs of your infrastructure?&lt;/P&gt;&lt;P&gt;For this job is usually requested&amp;nbsp; at least a Splunk Architect, this isn't a job for the Community.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 09:34:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Increasing-Replication-and-Search-Factor/m-p/616639#M26215</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-11T09:34:36Z</dc:date>
    </item>
  </channel>
</rss>

