Deployment Architecture

Should the SoS indexes be replicated in the cluster?

messes
Engager

I get that SoS needs to be installed separately across the search-heads, peers and master. But should the sos and sos_summary_daily indexes be added to the cluster replicated indexes?

Thanks

Tags (2)

hexx
Splunk Employee
Splunk Employee

There's no intrinsic need to replicate those indexes unless you want to ensure that they data they hold - the output of S.o.S scripted inputs - is resilient to one or more indexer failures.

You do need the indexes to be at the least defined on the peers if you plan to run the S.o.S scripted inputs there. The replication factor they should be subjected to is up to you.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...