<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help with changing tsidxWritingLevel in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Help-with-changing-tsidxWritingLevel/m-p/625281#M26494</link>
    <description>&lt;P&gt;Hello Splunkers /&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/68181"&gt;@DavidHourani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a single site indexer cluster with 2 Indexers which are having storage issues so we decided to apply below parameters.&lt;/P&gt;&lt;P&gt;We are currently on Splunk version 8.1.7&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&lt;SPAN&gt;tsidxWritingLevel = 4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2.&amp;nbsp;&lt;/SPAN&gt;enableTsidxReduction = true&lt;/P&gt;&lt;P&gt;3. timePeriodInSecBeforeTsidxReduction =&amp;nbsp;7890000&lt;/P&gt;&lt;P&gt;The issue here is from cluster Master i can see RF/SF is not met and 1 of the IDX is in Automatic-detention mode, so in this scenario what challenges will i face if above parameters are enabled for all the existing indexes.&lt;/P&gt;&lt;P&gt;Splunk docs doesn't tell much about RF/SF with these parameters.&lt;/P&gt;</description>
    <pubDate>Mon, 26 Dec 2022 18:42:28 GMT</pubDate>
    <dc:creator>splunk_noob2022</dc:creator>
    <dc:date>2022-12-26T18:42:28Z</dc:date>
    <item>
      <title>Help with changing tsidxWritingLevel</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Help-with-changing-tsidxWritingLevel/m-p/625281#M26494</link>
      <description>&lt;P&gt;Hello Splunkers /&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/68181"&gt;@DavidHourani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a single site indexer cluster with 2 Indexers which are having storage issues so we decided to apply below parameters.&lt;/P&gt;&lt;P&gt;We are currently on Splunk version 8.1.7&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&lt;SPAN&gt;tsidxWritingLevel = 4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2.&amp;nbsp;&lt;/SPAN&gt;enableTsidxReduction = true&lt;/P&gt;&lt;P&gt;3. timePeriodInSecBeforeTsidxReduction =&amp;nbsp;7890000&lt;/P&gt;&lt;P&gt;The issue here is from cluster Master i can see RF/SF is not met and 1 of the IDX is in Automatic-detention mode, so in this scenario what challenges will i face if above parameters are enabled for all the existing indexes.&lt;/P&gt;&lt;P&gt;Splunk docs doesn't tell much about RF/SF with these parameters.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Dec 2022 18:42:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Help-with-changing-tsidxWritingLevel/m-p/625281#M26494</guid>
      <dc:creator>splunk_noob2022</dc:creator>
      <dc:date>2022-12-26T18:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Help with changing tsidxWritingLevel</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Help-with-changing-tsidxWritingLevel/m-p/625291#M26495</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252282"&gt;@splunk_noob2022&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If an indexer has just gone into detention then most likely the "RF/SF not met" issue is linked to the CM trying to rebuild the buckets lost along with that indexer.&lt;/P&gt;&lt;P&gt;The parameters you posted are simply tuning for the indexes configuration and shouldn't have any effect on RF/SF being met.&lt;/P&gt;&lt;P&gt;Could you please check in your internal logs for the indexer that is in delention to see what other issues could be causing this?&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 04:31:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Help-with-changing-tsidxWritingLevel/m-p/625291#M26495</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2022-12-27T04:31:34Z</dc:date>
    </item>
  </channel>
</rss>

