Deployment Architecture

Clarification on Clustering & Index Replication

rturk
Builder

Hi All,

In reading a recently posted (16 Oct 2013) Splunk blog post "Clustering Optimizations in Splunk 6", the following was mentioned:

In the previous Splunk 5 version, users will not be able to search and
use the cluster until the cluster master ensures that all of the
replication policies are met. In some cases, this might take long time and
users are unnecessarily blocked until then.

Should I take this to mean that in v5, functional Index replication & searchability is only possible when you have n+1 indexers (where n is the index replication factor)? For example, if I have two indexers, and have set an index replication & searchability factor of two, this won't actually work as expected (i.e. full data availability in the event of a single indexer failure).

Any input is appreciated 🙂

mahamed_splunk
Splunk Employee
Splunk Employee

For example, if I have two indexers, and have set an index replication & searchability factor of two, this won't actually work as expected

No, If your replication policy is set to 2 and you have 2 indexers available, then your policy is already met, so users will be able to access and search the data.

rashid47010
Communicator

Hi
I have two index instances and one seach head
Now i want to configure replication and failover between these teo indexers.
How can i achieve this ?

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

Got it. Even if only one indexer is available, the data will continue to be available and searchable. The optimization the blog post talks about is the order in which we fix indexes and commit generations.

rturk
Builder

Hi Mahamed - I understand that if both of my indexers are available it will work, my question concerns the platform behaviour if one indexer has failed (e.g. "work as expected (i.e. full data availability in the event of a single indexer failure)."

0 Karma

rturk
Builder

FYI I have logged a support case for this and will report back with any findings.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...