Deployment Architecture

After Migrate single site to multisite Indexer cluster

Mitesh_Gajjar
Explorer

If facing issue after migrating single site to multisite indexer cluster. SF/RF not met after 5 days still fixup task increasing. Can any help to resolve this SF/RF issue ? 

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Mitesh_Gajjar 

More details needed pls

- The Splunk Version  

- the daily license limit

- approx how long back the Splunk was installed(to find out how much data is currently stored inside the Splunk)

- details about indexer/SHC pls (to understand how many indexers are in Indexer Cluster)
- the SF and RF pls 

and the most important - the internal splunk logs

may i know if you have created a Support ticket to Splunk pls. 


Best Regards

Sekar

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

dural_yyz
Builder

You really need to investigate your internal logs for bucket replication messages to get an idea of what is happening or not happening.  There are so many contributing factors to what could be occurring it would be difficult to provide an answer at this point.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...