Deployment Architecture

Are there any other reasons to have a search factor not equal to replication factor?

fredclown
Builder

If space is not really an issue are there any other reasons to have the search factor lower that the replication factor? Thanks.

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @fredclown,

no, the only reason is storage saving because indexes are the most part of storage occupation (row data iare around 15% of the original data and indexes are around 35% or the original data).

if you haven't storage occupation problems, you can use the same SF and RF.

Ciao.

Giuseppe

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

This is really a border case but remember that indexes are built independently on each indexer so if you have SF=RF=8, you use CPU time for indexing on 8 indexers whereas if you have RF=8 but SF=2, you just stream the data to 6 indexers and store it and only on 2 indexers you prepare searchable indexed data for the bucket.

As I said, it's a border case since often the difference across your environment will be insignificant but there is a difference.

Also remember that only primary copy of the bucket participates in search so having a high SF lets you recover from disaster easier but doesn't speed up searches.

gcusello
SplunkTrust
SplunkTrust

Hi @fredclown,

no, the only reason is storage saving because indexes are the most part of storage occupation (row data iare around 15% of the original data and indexes are around 35% or the original data).

if you haven't storage occupation problems, you can use the same SF and RF.

Ciao.

Giuseppe

fredclown
Builder

Thanks sir.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...