Deployment Architecture

How to reduce the search factor to 2 from 3?

arunsunny
Path Finder

Hello Splunkers,

I have one requirement where have 3 sites and planning to keep the search factor to 2 and replication factor to 3.

Current Config: ( SF=3 and RF=3 )

[clustering]
site_replication_factor = origin:1,site1:1,site2:1,site3:1,total:3
site_search_factor = origin:1,site1:1,site2:1,site3:1,total:3

 

To making into the Search Factor to 2 in any sites will the below settings works?

[clustering]
site_replication_factor = origin:1,site1:1,site2:1,site3:1,total:3
site_search_factor = origin:1,site1:1,site2:1,site3:1,total:2

To reduce to SF=2 what all steps involved?


Cheers,
Arun Sunny

 

 

 

richgalloway
SplunkTrust
SplunkTrust

The proposed site_search_factor setting is invalid.  One cannot have a copy on each of three sites and have a total of 2 copies.  I suggest 

site_search_factor = origin:1,total:2
---
If this reply helps you, Karma would be appreciated.

arunsunny
Path Finder

@richgalloway 

One more question:

If we are going to use the below settings:

site_search_factor = origin:1,total:2

 

Is there a chance of 2 search copy will be there on the same site?

 

richgalloway
SplunkTrust
SplunkTrust

Splunk will put one copy on the original site and the other copy on the other site.

---
If this reply helps you, Karma would be appreciated.
0 Karma

arunsunny
Path Finder

Hey @richgalloway ,

Thanks for the answer.

So post-change the config only Cluster master required restart?

0 Karma

richgalloway
SplunkTrust
SplunkTrust
Yes
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...