Deployment Architecture

How do you add replication to a pre-existing index?

a238574
Path Finder

I inherited a Splunk cluster that has some custom indexes that were created without setting repFactor=auto. Is it safe for me to update the config and push out the modified config for the impacted indexes?

0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

You can add that setting to existing indexes. New buckets will be index cluster buckets and replicate. The previous buckets will remain as standalone buckets, will be searchable, but will not replicate. As an example:

DB Directory for an index on an index cluster member, index is not configured with repFactor=auto

Oct  4 10:38 db_1538594348_1538594348_0

After adding 'repFactor=auto

Oct  4 10:38 db_1538594348_1538594348_0
Oct  4 10:42 db_1538594348_1538594348_1_81D21F8E-64D7-4ACB-962A-3CB331958491

DB Inspect:

alt text

Jacob
Sr. Technical Support Engineer
0 Karma

ddrillic
Ultra Champion

I don't see any problems.

I would run first on the one of the indexers - ./splunk btool indexes list --debug

That would show you the entire set-up of your indexes. By default for indexes where repFactor was not defined you should see repFactor = 0.

From Managing Indexers and Clusters of Indexers
and for the sake of completeness alt text

0 Karma

harsmarvania57
SplunkTrust
SplunkTrust

I guess you can assign repFactor = auto to existing indexes but I think only new buckets will be replicated to other indexers. I'll recommend to test this in test environment first.

0 Karma

a238574
Path Finder

I had read somewhere that it might not replicate existing buckets. Is there a way to get those buckets replicated

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...