Deployment Architecture

Indexer Cluster Replication Question

aaronhernandez
Explorer

Hello!

I am looking for your help. I have 2 indexer nodes in a splunk indexer cluster with rf=2 and sf=2 and we want to add 2 more nodes to this site, I only have one virtual site. I need your help because I want to update the rf to 3.
So by adding a new node and updating the rf, the historical data from the 2 oldest nodes will be replicated to the new nodes to meet the replication factor?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

yes, for my knowledge the old replicated data will be replicated to more indexers when you add more peers and you change the Replication Factor.

it's the same situation that you have when you have a down server.

The only requirement is that those indexes are in alredy in replication so the buckets are already replicated between peers.

It's different if you have not replicated old data that's not possible to replicate, e.g. when you create the cluster from two stand alone Indexers the old data aren't replicated.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

yes, for my knowledge the old replicated data will be replicated to more indexers when you add more peers and you change the Replication Factor.

it's the same situation that you have when you have a down server.

The only requirement is that those indexes are in alredy in replication so the buckets are already replicated between peers.

It's different if you have not replicated old data that's not possible to replicate, e.g. when you create the cluster from two stand alone Indexers the old data aren't replicated.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...