Deployment Architecture

After Migrate single site to multisite Indexer cluster

Mitesh_Gajjar
Explorer

If facing issue after migrating single site to multisite indexer cluster. SF/RF not met after 5 days still fixup task increasing. Can any help to resolve this SF/RF issue ? 

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Mitesh_Gajjar 

More details needed pls

- The Splunk Version  

- the daily license limit

- approx how long back the Splunk was installed(to find out how much data is currently stored inside the Splunk)

- details about indexer/SHC pls (to understand how many indexers are in Indexer Cluster)
- the SF and RF pls 

and the most important - the internal splunk logs

may i know if you have created a Support ticket to Splunk pls. 


Best Regards

Sekar

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

dural_yyz
Builder

You really need to investigate your internal logs for bucket replication messages to get an idea of what is happening or not happening.  There are so many contributing factors to what could be occurring it would be difficult to provide an answer at this point.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...