Deployment Architecture

Indexer Cluster Replication Question

aaronhernandez
Explorer

Hello!

I am looking for your help. I have 2 indexer nodes in a splunk indexer cluster with rf=2 and sf=2 and we want to add 2 more nodes to this site, I only have one virtual site. I need your help because I want to update the rf to 3.
So by adding a new node and updating the rf, the historical data from the 2 oldest nodes will be replicated to the new nodes to meet the replication factor?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

yes, for my knowledge the old replicated data will be replicated to more indexers when you add more peers and you change the Replication Factor.

it's the same situation that you have when you have a down server.

The only requirement is that those indexes are in alredy in replication so the buckets are already replicated between peers.

It's different if you have not replicated old data that's not possible to replicate, e.g. when you create the cluster from two stand alone Indexers the old data aren't replicated.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

yes, for my knowledge the old replicated data will be replicated to more indexers when you add more peers and you change the Replication Factor.

it's the same situation that you have when you have a down server.

The only requirement is that those indexes are in alredy in replication so the buckets are already replicated between peers.

It's different if you have not replicated old data that's not possible to replicate, e.g. when you create the cluster from two stand alone Indexers the old data aren't replicated.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...