Deployment Architecture

How to stop site replication when using multisite cluster? (just only need local site replication)

hkhat5
New Member

Dear all,

I have site1 and site2 with multisite cluster on.
However, i just only want to replicate the data within local site only.

What and how to configure that setup?

Thanks
Kelvin

Tags (2)
0 Karma

dxu_splunk
Splunk Employee
Splunk Employee

you can set site_replication_factor and site_search_factor's origin:N and total:N to be the same.
for example:

site_replication_factor = origin:2, total:2
site_search_factor = origin:1, total:1

hkhat5
New Member
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Although, I do believe that if one site doesn't have enough servers, it will try to replicate to the other. Maybe you want this, maybe you don't.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

This is a better answer than mine.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I don't understand what you're asking for. Why are you using multi-site clustering in the first place? Why don't you just create two separate clusters?

0 Karma

hkhat5
New Member

gkanapathy, thanks for your reply.

Just like you said, create 2 two separate clusters.
Can it control by single master node?
Also, can it search all the result with one search head?

Thanks

Kelvin

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You can search both with one search head, but you need two masters, one for each cluster.

0 Karma

hkhat5
New Member

Do you mean that install external search head just outside the 2 clusters?
Thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...