Deployment Architecture

If a peer goes down in an indexer cluster, how does new indexed data get replicated, and what happens when the peer comes back up later?

splunkn
Communicator

Little confused in Indexer Clustering. I have 3 peers with One master and One Search Head. Replication Factor is 3 and Search Factor is 2. If one of the indexers goes down, Master can manage with 2 searchable copies by moving the primacy and convert non-searchable into searchable. Search Factor is good, but in this case, my rep factor is 3 and number of peers also 3. If one of the peers goes down, RF could not be met and this cluster is valid, but incomplete. Two questions here:

  1. If new data comes, how does it get replicated? Is it going to store only two copies of data in available indexers (one original + one replicated)?

  2. What happen if my downed peer came back after one week? Whether the new data captured during last week is going to get copied in this peer?

Thanks in advance

0 Karma

jmallorquin
Builder

Hi,

For replication factor 3 you need 3 peers, in this case if your peers goes down the replication factor is not meet until you add other indexer, but your search factor will be meet after the fix process.

When your down peer goes up the master will rebuild the cluster make all the copies needed and yes after the rebuild all your peers will have a copy of the indexed data doesn't matter the time was down the indexer.

Hope i help you

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...