Deployment Architecture

Indexers cluster: Data synchronization after failure



I am creating an indexer cluster (2 peers and replication factor=2) and I need to know:

  1. If one of the peers is down, the other one keep receiving events (from the sources or HF) and responding searches to the Search Head right?

  2. When the peer is up again, does it receive the events generated during the time it was down? Or they will only reside in the peer that was up all the time?

  3. Do we need to backup both indexers although they have the same data?

Thank you very much.

0 Karma


Thank you very much.

I've been reading what you sent me and I think that the answers are:

  1. YES
  2. YES
  3. ?

Is that correct?

Thank's again.

0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...