Deployment Architecture

Recommended search/replication factor config for 2 site index cluster w/16 indexers each

joesrepsolc
Communicator

Looking for any performance gains on our architecture and how best to take advantage of the (16) indexer clusters we have in place (1 cluster in CA, and another in midwest)

Today the replication factor = 2, and search factor = 2. Feeling like we can do better and increase performance.

Thoughts? Reasoning?

Thanks!

0 Karma

lakshman239
Influencer

Assuming you have multi-site indexer cluster across 2 sites, what's your site search and replication factor? How many copies do you want to store in each site when a new data comes in? Look at your failover and storage considerations.

e.g. any data coming in site 1 can be stored in 2 indexers (or more if you want) in the originating site and another 2 copies in the other site. This will ensure equal amount of data in each site and fault tolerant up-to 2 nodes in a site.

Look at the examples in https://docs.splunk.com/Documentation/Splunk/7.2.3/Indexer/Sitereplicationfactor#Examples and your use cases, available storage to determine/adust Site SF/RF. Generally, distributing the copies equivally in both sites should give you a better performance. Also, if the users are across the world, you may also need to look at balancing them to both sites equally

https://docs.splunk.com/Documentation/Splunk/7.2.3/Indexer/Sitesearchfactor

0 Karma

bangalorep
Communicator

Are you facing any performance issues?
Also, what is the data volume?

0 Karma

joesrepsolc
Communicator

no performance problems persay... but something I want to understand better. Obviously looking for as-best of performance as possible out of our system. Doing roughly 4TB/day ingestion.

0 Karma

adonio
Ultra Champion

are those connected? e.g. multi-site cluster or separate indexer clusters?

0 Karma

joesrepsolc
Communicator

It is a multi-site index cluster. (16) indexers at one site and (16) indexers at another site. All managed by a single cluster master.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...