- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have a distributed splunk deployment with search-head cluster, indexer cluster and forwarders. Currently, the main index is not replicated across the index cluster peers. Is that recommended (or the inverse, NOT recommended)?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


I would say "yes", if only for consistency's sake. Ideally little if any data winds up being stored in the main index - but if some does wind up there by accident (or misconfigured app), then it'd be really nice were it replicated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


I would say "yes", if only for consistency's sake. Ideally little if any data winds up being stored in the main index - but if some does wind up there by accident (or misconfigured app), then it'd be really nice were it replicated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Exactly... it's the only index that you could "accidentally" put something in... which implies it should be treated like an "intentional" and replicated index. 🙂
