Deployment Architecture

Multisite Indexer Clustering: Can a Site be decommissioned after it has been Operational? What will be the impact?

rbal_splunk
Splunk Employee
Splunk Employee

Current Environment has an Indexer Clustering Multisite setup with Site 1 and Site 2. We plan to decommission site 2 and wanted to know the impact on Indexer Clustering.

0 Karma
1 Solution

rbal_splunk
Splunk Employee
Splunk Employee

Please note currently multi-site buckets are bonded (has persistent binding) to Originating Site.

As a result once site is created it cannot be decommissioned or else the buckets Originating from that site will never meet the Search and Replication Factor.

Splunk has pending Enhancement Bug requesting that bonding should be broken and it should be more flexible to copy/move bucket between sites. For your reference enhancement Request is --SPL-110192:Multi-site buckets should not be bonded to Originating Site.

View solution in original post

rbal_splunk
Splunk Employee
Splunk Employee

Please note currently multi-site buckets are bonded (has persistent binding) to Originating Site.

As a result once site is created it cannot be decommissioned or else the buckets Originating from that site will never meet the Search and Replication Factor.

Splunk has pending Enhancement Bug requesting that bonding should be broken and it should be more flexible to copy/move bucket between sites. For your reference enhancement Request is --SPL-110192:Multi-site buckets should not be bonded to Originating Site.

Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...