Deployment Architecture

How to reduce the search factor to 2 from 3?

arunsunny
Path Finder

Hello Splunkers,

I have one requirement where have 3 sites and planning to keep the search factor to 2 and replication factor to 3.

Current Config: ( SF=3 and RF=3 )

[clustering]
site_replication_factor = origin:1,site1:1,site2:1,site3:1,total:3
site_search_factor = origin:1,site1:1,site2:1,site3:1,total:3

 

To making into the Search Factor to 2 in any sites will the below settings works?

[clustering]
site_replication_factor = origin:1,site1:1,site2:1,site3:1,total:3
site_search_factor = origin:1,site1:1,site2:1,site3:1,total:2

To reduce to SF=2 what all steps involved?


Cheers,
Arun Sunny

 

 

 

richgalloway
SplunkTrust
SplunkTrust

The proposed site_search_factor setting is invalid.  One cannot have a copy on each of three sites and have a total of 2 copies.  I suggest 

site_search_factor = origin:1,total:2
---
If this reply helps you, Karma would be appreciated.

arunsunny
Path Finder

@richgalloway 

One more question:

If we are going to use the below settings:

site_search_factor = origin:1,total:2

 

Is there a chance of 2 search copy will be there on the same site?

 

richgalloway
SplunkTrust
SplunkTrust

Splunk will put one copy on the original site and the other copy on the other site.

---
If this reply helps you, Karma would be appreciated.
0 Karma

arunsunny
Path Finder

Hey @richgalloway ,

Thanks for the answer.

So post-change the config only Cluster master required restart?

0 Karma

richgalloway
SplunkTrust
SplunkTrust
Yes
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...