<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Install ES on an Indexers Cluster in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Install-ES-on-an-Indexers-Cluster/m-p/545195#M9819</link>
    <description>&lt;P&gt;I think that in an Indexer Cluster by default all the Splunk "internal" indexes should have repFactor=auto, at least under&amp;nbsp;&lt;SPAN&gt;/opt/splunk/etc/master-apps/_cluster/default/indexes.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I opened the following Splunk Idea to ask for the implementation:&lt;/P&gt;&lt;P&gt;&lt;A href="https://ideas.splunk.com/ideas/EID-I-898" target="_blank"&gt;https://ideas.splunk.com/ideas/EID-I-898&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Mar 2021 17:36:47 GMT</pubDate>
    <dc:creator>edoardo_vicendo</dc:creator>
    <dc:date>2021-03-24T17:36:47Z</dc:date>
    <item>
      <title>Install ES on an Indexers Cluster</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Install-ES-on-an-Indexers-Cluster/m-p/484654#M7948</link>
      <description>&lt;P&gt;Hi at all,&lt;BR /&gt;
probably it's a stupid question, but I don't know very well if ES has special requirements for Indexers Clusters and documentation doesn't help me.&lt;BR /&gt;
I took in charge a Splunk installation where I found an Indexers Cluster where is installed the Splunk_TA_ForIndexers containing the indexes.conf file for ES correctly deployed using Master Node.&lt;BR /&gt;
The problem is that in indexes.conf there isn't the clause repFactor = auto in indexes stanzas, so indexes aren't replicated between the cluster!&lt;BR /&gt;
I know that old events aren't replicated between Indexers, so what it will happen if I insert the clause in indexes.conf?&lt;/P&gt;

&lt;P&gt;Thank you for your help.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:14:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Install-ES-on-an-Indexers-Cluster/m-p/484654#M7948</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-30T02:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Install ES on an Indexers Cluster</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Install-ES-on-an-Indexers-Cluster/m-p/484655#M7949</link>
      <description>&lt;P&gt;from the moment you insert the clause, data will replicate according to policies&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 15:51:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Install-ES-on-an-Indexers-Cluster/m-p/484655#M7949</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-09-20T15:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Install ES on an Indexers Cluster</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Install-ES-on-an-Indexers-Cluster/m-p/484656#M7950</link>
      <description>&lt;P&gt;If you want to modify indexes.conf to add repFactor = auto, follow these steps to recreate the Splunk_TA_ForIndexers and modify the indexes.conf outputted in that package, then deploy that updated package to your indexer cluster. &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/ES/5.3.1/Install/InstallTechnologyAdd-ons#Create_the_Splunk_TA_ForIndexers_and_manage_deployment_manually" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/5.3.1/Install/InstallTechnologyAdd-ons#Create_the_Splunk_TA_ForIndexers_and_manage_deployment_manually&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The likely reason this is not set to auto is because repFactor is set to 0 by default, and the Splunk_TA_ForIndexers indexes.conf file combines the indexes.conf files in the add-ons selected when the TA is created. So if the indexes.conf files in those add-ons weren't set to replicate, it wouldn't get added. &lt;/P&gt;

&lt;P&gt;I hope this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:19:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Install-ES-on-an-Indexers-Cluster/m-p/484656#M7950</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2020-09-30T02:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: Install ES on an Indexers Cluster</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Install-ES-on-an-Indexers-Cluster/m-p/545195#M9819</link>
      <description>&lt;P&gt;I think that in an Indexer Cluster by default all the Splunk "internal" indexes should have repFactor=auto, at least under&amp;nbsp;&lt;SPAN&gt;/opt/splunk/etc/master-apps/_cluster/default/indexes.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I opened the following Splunk Idea to ask for the implementation:&lt;/P&gt;&lt;P&gt;&lt;A href="https://ideas.splunk.com/ideas/EID-I-898" target="_blank"&gt;https://ideas.splunk.com/ideas/EID-I-898&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 17:36:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Install-ES-on-an-Indexers-Cluster/m-p/545195#M9819</guid>
      <dc:creator>edoardo_vicendo</dc:creator>
      <dc:date>2021-03-24T17:36:47Z</dc:date>
    </item>
  </channel>
</rss>

