Deployment Architecture

Should the main index be replicated in an indexer cluster?

transtrophe
Communicator

I have a distributed splunk deployment with search-head cluster, indexer cluster and forwarders. Currently, the main index is not replicated across the index cluster peers. Is that recommended (or the inverse, NOT recommended)?

1 Solution

dwaddle
SplunkTrust
SplunkTrust

I would say "yes", if only for consistency's sake. Ideally little if any data winds up being stored in the main index - but if some does wind up there by accident (or misconfigured app), then it'd be really nice were it replicated.

View solution in original post

dwaddle
SplunkTrust
SplunkTrust

I would say "yes", if only for consistency's sake. Ideally little if any data winds up being stored in the main index - but if some does wind up there by accident (or misconfigured app), then it'd be really nice were it replicated.

rsennett_splunk
Splunk Employee
Splunk Employee

Exactly... it's the only index that you could "accidentally" put something in... which implies it should be treated like an "intentional" and replicated index. 🙂

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...