Deployment Architecture

Getting rid of Index Clustering

splunk_kk
Path Finder

Hi Team,

I have a single site Indexer clustering in place. I have two indexers and one search head as the members. I want to get rid of Cluster master and eventually Index clustering. I need my Indexers to work independently and share the load.

At the moment my SF=2 and RF=2

What is the best way to achieve this with no/minimum data loss.

Thanks!

0 Karma

deepashri_123
Motivator

@splunk_kk,
Is there any reason to remove indexer clustering? Removing indexer clustering will lead to no data replication across indexers and there will be no high availability of data.

0 Karma

livehybrid
Builder

Hi,
Are you planning to continue indexing to both indexers once your remove indexer clustering, or just one at once?
Dont forget that you'll end up using twice your license amount if you index it on multiple indexers that arent in a cluster.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...