Deployment Architecture

Search Affinity Disabled on multisite cluster : Search results are incomplete

amey2407
Splunk Employee
Splunk Employee

Hi,

We have a multisite cluster with 1 indexer on each site with 1 SH on primary site. Currently, when search affinity is enabled and we run a search for index "crowdstrike" , we can see past 30 days data. But when search affinity is disabled on the search head, the same search displays recent data and not the past 30 days.

Question: Is there something missing configuration wise?

Labels (2)
0 Karma

manikumarv
Explorer

Were you able to get this resolved?  We are experiencing the same when search affinity is disabled.

0 Karma

amey2407
Splunk Employee
Splunk Employee
@manikumarv Following were the steps followed by customer to resolve the issue. Hope this helps.
 
Apparently, the key steps are the ones highlighted below.
 

image (2).png

 
At the start of the MW, I've tried to add the search_factor=2 and restarted the CM for it to take effect, then to disable SA and restarted the SH.
Waited 10 mins or so but still the outcome was the same as before.
 
But I tried restarting the CM again, to ensure that all steps were followed to the key.
Almost immediately, the old events appeared.
 
Before
 

image (1).png

 
After
 

image.png

 
Tags (1)

manikumarv
Explorer

@amey2407 Thanks for the details.

We do have the [single-site] SF setting already on the CM as you noted.  But I did not try restarting CM after disabling SA on the SH.  I'll give that a try and let you know.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...