Deployment Architecture

After setting replication factor to 2 at the global level, can I turn it off for some indexers?

jwalthour
Communicator

After setting repFactor = 2 at the default level and running with that for awhile, can I now go in on a per indexer basis and set repFactor = 0 on some indexers so that only a few are replicating at a time and I can phase in index replication?

0 Karma
1 Solution

Steve_G_
Splunk Employee
Splunk Employee

No. The repFactor setting must be the same across all peers in the cluster. All cluster peer nodes must set repfactor=auto for all clustered indexes.

See http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/Configurethepeerindexes

View solution in original post

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@jwalthour - Did the answer provided by Steve G. help provide a solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

somesoni2
Revered Legend

Replication factor two means the cluster maintains 2 copies of all raw data, not that all indexers maintain a copy of data separately. Any specific reason you want to have some indexers not take part in replication (or not be part of cluster if they are not replicating)?

0 Karma

Steve_G_
Splunk Employee
Splunk Employee

No. The repFactor setting must be the same across all peers in the cluster. All cluster peer nodes must set repfactor=auto for all clustered indexes.

See http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/Configurethepeerindexes

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...