Deployment Architecture

What is origin when setting a Multisite Indexer Cluster?

ddrillic
Ultra Champion

What is origin? I just don't understand what it means...

As in the command -

~/cmaster/bin/splunk edit cluster-config -mode master -multisite true 
-site site1 -available_sites site1,site2 -site_replication_factor origin:1,total:2 -site_search_factor origin:1,total:2 -replication_factor 1 -search_factor 1 -secret xxxx
Tags (2)
0 Karma
1 Solution

somesoni2
SplunkTrust
SplunkTrust

The 'origin' refers to the site which contains the original raw data (bucket). The term -site_replication_factor origin:1,total:2 means that there will be 1 copy of raw data bucket in the site where data was originated (indexed) (1 copy means just the original copy) and there will be a total of 2 copied of that data available in the cluster (so since origin site has 1, other 1 copy (2-1=1) will be replicated to other site(s)).

View solution in original post

somesoni2
SplunkTrust
SplunkTrust

The 'origin' refers to the site which contains the original raw data (bucket). The term -site_replication_factor origin:1,total:2 means that there will be 1 copy of raw data bucket in the site where data was originated (indexed) (1 copy means just the original copy) and there will be a total of 2 copied of that data available in the cluster (so since origin site has 1, other 1 copy (2-1=1) will be replicated to other site(s)).

ddrillic
Ultra Champion

Crystal clear as always - thank you @somesoni2 !!!

0 Karma

ddrillic
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...