Deployment Architecture

Index cluster with only two search peers

Julieda
Explorer

Does anyone have experience with index clusters that only contain two indexers? In splunk docs, and in most other forums, the only examples of clusters contain at least three nodes. But shouldn't it function with only two indexers as well? What would be the potential disadvantages, besides less redundancy and reliability?

0 Karma
1 Solution

lguinn2
Legend

The default replication factor is three, so all the examples tend to show at least 3 indexers. However, AFAIK there is no restriction: you can have an index cluster with only 2 search peers (indexers). Just be sure to set the replication factor and search factor appropriately.

IMO, the only disadvantage (besides the ones you mention) would be: you must have a search head and a cluster master to complete your indexer cluster. So only half of your assets are actually indexing. I think you would get more for your money if you had a greater number of indexers. OTOH, you may have an initial installation with 2 indexers and plans to grow...

View solution in original post

Steve_G_
Splunk Employee
Splunk Employee

Regarding the number of indexers, or peer nodes, the only requirement is that you have at least as many as the replication factor. For details, see:

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Systemrequirements#Required_Splunk_Enterp...

0 Karma

Julieda
Explorer

Great. Thanks!

0 Karma

lguinn2
Legend

The default replication factor is three, so all the examples tend to show at least 3 indexers. However, AFAIK there is no restriction: you can have an index cluster with only 2 search peers (indexers). Just be sure to set the replication factor and search factor appropriately.

IMO, the only disadvantage (besides the ones you mention) would be: you must have a search head and a cluster master to complete your indexer cluster. So only half of your assets are actually indexing. I think you would get more for your money if you had a greater number of indexers. OTOH, you may have an initial installation with 2 indexers and plans to grow...

Julieda
Explorer

Ok, great! It is good to know that this will function before the configuration begins, as I only have a production environment available. Hopefully the plan is to grow the number of indexers eventually. Thank you for answering so quickly!

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...