Deployment Architecture

How to reduce the search factor to 2 from 3?

arunsunny
Path Finder

Hello Splunkers,

I have one requirement where have 3 sites and planning to keep the search factor to 2 and replication factor to 3.

Current Config: ( SF=3 and RF=3 )

[clustering]
site_replication_factor = origin:1,site1:1,site2:1,site3:1,total:3
site_search_factor = origin:1,site1:1,site2:1,site3:1,total:3

 

To making into the Search Factor to 2 in any sites will the below settings works?

[clustering]
site_replication_factor = origin:1,site1:1,site2:1,site3:1,total:3
site_search_factor = origin:1,site1:1,site2:1,site3:1,total:2

To reduce to SF=2 what all steps involved?


Cheers,
Arun Sunny

 

 

 

richgalloway
SplunkTrust
SplunkTrust

The proposed site_search_factor setting is invalid.  One cannot have a copy on each of three sites and have a total of 2 copies.  I suggest 

site_search_factor = origin:1,total:2
---
If this reply helps you, Karma would be appreciated.

arunsunny
Path Finder

@richgalloway 

One more question:

If we are going to use the below settings:

site_search_factor = origin:1,total:2

 

Is there a chance of 2 search copy will be there on the same site?

 

richgalloway
SplunkTrust
SplunkTrust

Splunk will put one copy on the original site and the other copy on the other site.

---
If this reply helps you, Karma would be appreciated.
0 Karma

arunsunny
Path Finder

Hey @richgalloway ,

Thanks for the answer.

So post-change the config only Cluster master required restart?

0 Karma

richgalloway
SplunkTrust
SplunkTrust
Yes
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...