Deployment Architecture

Indexer Cluster Replication Question

aaronhernandez
Explorer

Hello!

I am looking for your help. I have 2 indexer nodes in a splunk indexer cluster with rf=2 and sf=2 and we want to add 2 more nodes to this site, I only have one virtual site. I need your help because I want to update the rf to 3.
So by adding a new node and updating the rf, the historical data from the 2 oldest nodes will be replicated to the new nodes to meet the replication factor?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

yes, for my knowledge the old replicated data will be replicated to more indexers when you add more peers and you change the Replication Factor.

it's the same situation that you have when you have a down server.

The only requirement is that those indexes are in alredy in replication so the buckets are already replicated between peers.

It's different if you have not replicated old data that's not possible to replicate, e.g. when you create the cluster from two stand alone Indexers the old data aren't replicated.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

yes, for my knowledge the old replicated data will be replicated to more indexers when you add more peers and you change the Replication Factor.

it's the same situation that you have when you have a down server.

The only requirement is that those indexes are in alredy in replication so the buckets are already replicated between peers.

It's different if you have not replicated old data that's not possible to replicate, e.g. when you create the cluster from two stand alone Indexers the old data aren't replicated.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aaronhernandez,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

Get Updates on the Splunk Community!

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...