Deployment Architecture

Configure a dedicated server for all data replication

Nawab
Communicator

while configuring RF and SH, can we configure that only one server should be used for saving all copies of data and does not participate in indexing, only participate in searching when needed.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nawab,

no it isn't possible: in Splunk data are replicated between all the indexers (based on Replication Factor and Search Factor) and all the Indexers partecipate to searches.

You can choose the number of copies of replicated raw data (Replication Factor) that use around 15% or the original data and the number of copies of idxs (Replication Factor) that use around 35% or the original data.

For more infos see at https://docs.splunk.com/Documentation/Splunk/9.1.2/Indexer/Aboutclusters.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...