Deployment Architecture

Indexer Cluster Replication Question

aaronhernandez
Explorer

Hello!

I am looking for your help. I have 2 indexer nodes in a splunk indexer cluster with rf=2 and sf=2 and we want to add 2 more nodes to this site, I only have one virtual site. I need your help because I want to update the rf to 3.
So by adding a new node and updating the rf, the historical data from the 2 oldest nodes will be replicated to the new nodes to meet the replication factor?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

yes, for my knowledge the old replicated data will be replicated to more indexers when you add more peers and you change the Replication Factor.

it's the same situation that you have when you have a down server.

The only requirement is that those indexes are in alredy in replication so the buckets are already replicated between peers.

It's different if you have not replicated old data that's not possible to replicate, e.g. when you create the cluster from two stand alone Indexers the old data aren't replicated.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

yes, for my knowledge the old replicated data will be replicated to more indexers when you add more peers and you change the Replication Factor.

it's the same situation that you have when you have a down server.

The only requirement is that those indexes are in alredy in replication so the buckets are already replicated between peers.

It's different if you have not replicated old data that's not possible to replicate, e.g. when you create the cluster from two stand alone Indexers the old data aren't replicated.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...