<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Share index by NFS to multiple searchers in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Share-index-by-NFS-to-multiple-searchers/m-p/299527#M56662</link>
    <description>&lt;P&gt;Hello.&lt;BR /&gt;
I explain the scenario:&lt;BR /&gt;
I have 2 servers destined to different functions ServerA (receive and index, few searches) and ServerB (full searches)&lt;BR /&gt;
In particular, the ServerB will be the database with  /dbsplunk partition with 3TB.&lt;BR /&gt;
While the ServerA, it will receive the data and index it on the NFS /dbsplunk mounted drive from the ServerB.&lt;/P&gt;

&lt;P&gt;So far, the indexing works very well, the data is stored without problems. But when doing searches, both can search the buckets WARM or COLD, but bucket HOT can not be searched. I understand  because Splunk blocks the HOT at the time of writing, but I know that Splunk can replicate the HOT files so that other searchers can access the search (1 for each search), according to the following link: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.0/Indexer/HowSplunkstoresindexes#Bucket_names"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.0/Indexer/HowSplunkstoresindexes#Bucket_names&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;How could I get the ServerA and ServerB to search in bucket HOT at the same time. I know that in the indexes.conf file there is the parameter repFactor = auto, but I do not know how to get it.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Oct 2017 14:48:41 GMT</pubDate>
    <dc:creator>jrodriguezap</dc:creator>
    <dc:date>2017-10-06T14:48:41Z</dc:date>
    <item>
      <title>Share index by NFS to multiple searchers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Share-index-by-NFS-to-multiple-searchers/m-p/299527#M56662</link>
      <description>&lt;P&gt;Hello.&lt;BR /&gt;
I explain the scenario:&lt;BR /&gt;
I have 2 servers destined to different functions ServerA (receive and index, few searches) and ServerB (full searches)&lt;BR /&gt;
In particular, the ServerB will be the database with  /dbsplunk partition with 3TB.&lt;BR /&gt;
While the ServerA, it will receive the data and index it on the NFS /dbsplunk mounted drive from the ServerB.&lt;/P&gt;

&lt;P&gt;So far, the indexing works very well, the data is stored without problems. But when doing searches, both can search the buckets WARM or COLD, but bucket HOT can not be searched. I understand  because Splunk blocks the HOT at the time of writing, but I know that Splunk can replicate the HOT files so that other searchers can access the search (1 for each search), according to the following link: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.0/Indexer/HowSplunkstoresindexes#Bucket_names"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.0/Indexer/HowSplunkstoresindexes#Bucket_names&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;How could I get the ServerA and ServerB to search in bucket HOT at the same time. I know that in the indexes.conf file there is the parameter repFactor = auto, but I do not know how to get it.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 14:48:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Share-index-by-NFS-to-multiple-searchers/m-p/299527#M56662</guid>
      <dc:creator>jrodriguezap</dc:creator>
      <dc:date>2017-10-06T14:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: Share index by NFS to multiple searchers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Share-index-by-NFS-to-multiple-searchers/m-p/299528#M56663</link>
      <description>&lt;P&gt;will there be someone who has happened to him?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 15:16:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Share-index-by-NFS-to-multiple-searchers/m-p/299528#M56663</guid>
      <dc:creator>jrodriguezap</dc:creator>
      <dc:date>2017-10-09T15:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Share index by NFS to multiple searchers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Share-index-by-NFS-to-multiple-searchers/m-p/299529#M56664</link>
      <description>&lt;P&gt;Splunk does not handle that situation, as each indexer will try to manage the buckets, and generate conflicts.&lt;/P&gt;

&lt;P&gt;Why not use the indexes replication  cluster feature to have the indexes you want replicated on the 2 indexers (with replication and search factor 2) ?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 17:43:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Share-index-by-NFS-to-multiple-searchers/m-p/299529#M56664</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2017-10-09T17:43:51Z</dc:date>
    </item>
  </channel>
</rss>

