Deployment Architecture

How to stop site replication when using multisite cluster? (just only need local site replication)

hkhat5
New Member

Dear all,

I have site1 and site2 with multisite cluster on.
However, i just only want to replicate the data within local site only.

What and how to configure that setup?

Thanks
Kelvin

Tags (2)
0 Karma

dxu_splunk
Splunk Employee
Splunk Employee

you can set site_replication_factor and site_search_factor's origin:N and total:N to be the same.
for example:

site_replication_factor = origin:2, total:2
site_search_factor = origin:1, total:1

hkhat5
New Member
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Although, I do believe that if one site doesn't have enough servers, it will try to replicate to the other. Maybe you want this, maybe you don't.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

This is a better answer than mine.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I don't understand what you're asking for. Why are you using multi-site clustering in the first place? Why don't you just create two separate clusters?

0 Karma

hkhat5
New Member

gkanapathy, thanks for your reply.

Just like you said, create 2 two separate clusters.
Can it control by single master node?
Also, can it search all the result with one search head?

Thanks

Kelvin

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You can search both with one search head, but you need two masters, one for each cluster.

0 Karma

hkhat5
New Member

Do you mean that install external search head just outside the 2 clusters?
Thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...