Splunk Multisite Indexer Cluster - Disk Space and Bucket Retention

New Member

I plan to stand up a multisite indexer cluster in the future. In this cluster, I plan to provision each indexer node to have just enough disk space to hold a data with a replication factor of 4. If one node goes down and the master initiates bucket fixup, what will happen in this scenario? Since the cluster will not have enough disk space to maintain 4 valid copies of data, will the fixup simply fail or will older data be deleted off of existing indexers to make room?

Tags (1)
0 Karma