Deployment Architecture

How to maintain existing replication factors while adding new attributes while migrating from single site to multi-site indexer cluster?

keerthana_k
Communicator

Hi,

We are working on migrating a single site indexer cluster to multi-site indexer cluster. For this, we are using Splunk CLI to set the clustering attributes. We are using the following command:

splunk edit cluster-config -mode master -multisite true -available_sites site1,site2 -site site1 -site_replication_factor origin:2,total:3 -site_search_factor origin:1,total:2

However, running this command removes the existing replication factor and search factor entries that are present in the server.conf file. According to Splunk documentation, the replication and search factor values need to be present in the server.conf file to maintain pre-migration data.

Is there something we are doing wrong? How do we maintain the original factors while adding the new attributes for multi-site?

Thanks,
Keerthana

0 Karma

dxu_splunk
Splunk Employee
Splunk Employee

That command shouldn't overwrite the existing replication_factor and search_factor entries! What version are you running?

(if replication_factor and search_factor are not present, the default values should still be present from the default/server.conf btw. use btool to see what the current actual configs are and what files are providing them)

0 Karma

keerthana_k
Communicator

We are using splunk version 6.4.0. I am aware that replication and search factor entries are present in default/server.conf too but there might be a case where our customer would have set custom replication and search factors in his local/server.conf file.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...