Deployment Architecture

How to maintain existing replication factors while adding new attributes while migrating from single site to multi-site indexer cluster?

keerthana_k
Communicator

Hi,

We are working on migrating a single site indexer cluster to multi-site indexer cluster. For this, we are using Splunk CLI to set the clustering attributes. We are using the following command:

splunk edit cluster-config -mode master -multisite true -available_sites site1,site2 -site site1 -site_replication_factor origin:2,total:3 -site_search_factor origin:1,total:2

However, running this command removes the existing replication factor and search factor entries that are present in the server.conf file. According to Splunk documentation, the replication and search factor values need to be present in the server.conf file to maintain pre-migration data.

Is there something we are doing wrong? How do we maintain the original factors while adding the new attributes for multi-site?

Thanks,
Keerthana

0 Karma

dxu_splunk
Splunk Employee
Splunk Employee

That command shouldn't overwrite the existing replication_factor and search_factor entries! What version are you running?

(if replication_factor and search_factor are not present, the default values should still be present from the default/server.conf btw. use btool to see what the current actual configs are and what files are providing them)

0 Karma

keerthana_k
Communicator

We are using splunk version 6.4.0. I am aware that replication and search factor entries are present in default/server.conf too but there might be a case where our customer would have set custom replication and search factors in his local/server.conf file.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...