Deployment Architecture

Indexer Cluster Replication Question

aaronhernandez
Explorer

Hello!

I am looking for your help. I have 2 indexer nodes in a splunk indexer cluster with rf=2 and sf=2 and we want to add 2 more nodes to this site, I only have one virtual site. I need your help because I want to update the rf to 3.
So by adding a new node and updating the rf, the historical data from the 2 oldest nodes will be replicated to the new nodes to meet the replication factor?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

yes, for my knowledge the old replicated data will be replicated to more indexers when you add more peers and you change the Replication Factor.

it's the same situation that you have when you have a down server.

The only requirement is that those indexes are in alredy in replication so the buckets are already replicated between peers.

It's different if you have not replicated old data that's not possible to replicate, e.g. when you create the cluster from two stand alone Indexers the old data aren't replicated.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

yes, for my knowledge the old replicated data will be replicated to more indexers when you add more peers and you change the Replication Factor.

it's the same situation that you have when you have a down server.

The only requirement is that those indexes are in alredy in replication so the buckets are already replicated between peers.

It's different if you have not replicated old data that's not possible to replicate, e.g. when you create the cluster from two stand alone Indexers the old data aren't replicated.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...