All Apps and Add-ons

Can someone explain me the concept and calculation of replication and search factor?

abhi04
Communicator

I tried learning from splunk docs but did not understand.How to calculate the replication and search factor in a clustered environment?

0 Karma

deepashri_123
Motivator

Hey abhi04,

Replication factor defines how many replicated buckets you want .Suppose you have clustered environment of 3 indexers and if you keep replication factor as 3,then each indexer would have replicated copies of the other indexers.
If the indexer fails,the other two indexers will have the replicated copies and those will become searchable.Only the primary copies that were available in the indexer that failed, the other indexers would make only those copies searchable.

Search factor is the number of copies that you want to be available in Splunk.
Note: If the search factor is high, all the index files are replicated and that can account on your storage.
You need to decide replication factor and search factor as per how you want high availability to be set.

You can refer this doc for detailed explanation:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Indexer/Basicclusterarchitecture

Let me know if this helps!!

0 Karma

tiagofbmm
Influencer

Let's use a Single Site Cluster case.

The replication factor is total the number of copies of _raw data that exist in within the cluster members. If your cluster has 3 elements and you have a replication factor of 2, then you can be sure that 2 of your cluster members have one copy of a specific bucket (_raw)

The search factor is the number of "indexed data" meaning the structure that makes data searchable. The same thing applies, if you have a search factor of 2 in a 3 members cluster, then 2 of them have the indexed structure.

0 Karma

abhi04
Communicator

What is the formula for replication and search factor? And also wanted explanation in clustered environment.

Thanks for the answer.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...