Deployment Architecture

What is the procedure to remove a site from a 3 site indexer clustering environment?

gavsdavs_GR
Path Finder

I have a 3 site, 6 peer (2 in each) environment which I want to reduce to a 2 site, 4 peer environment due to my company needing to exit a datacentre.

I know I'm going to need to update Site Replication Factor, Site Search Factor, and available_sites in server.conf on my cluster master, and also offline --enforce-counts on my peers, but I do not know the right order to do this.

Do I tell my Cluster Master I'm now running in 2 sites whilst leaving all peers up across 3 sites THEN run offline --enforce-counts on the exiting peers
- OR -
Do I run offline --enforce-counts on my exiting peers and then go and reduce my CMs sites afterwards?

I anticipate either
- the CM getting upset about failing to meet SSF/SRF if I exit the peers first, or
- the CM getting confused by additional, unexpected peers talking to it if i reduce the CM's notion of sites first.

What order is this done in?

Thanks muchly !

0 Karma

gavsdavs_GR
Path Finder

javiergn
SplunkTrust
SplunkTrust

What are your SSF / SRF at the moment?
What sort of replication/resiliency are you planning to have in your 2-site deployment?

Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...