Hi,
Splunk documentation mentions that in case of site failure in a multisite indexer clustering deployment, the master maintains reserved copies of data to be assigned to peers of the non-functional site once it starts functioning again. Is there is any restriction on the time period upto which the reserved copy is kept alive waiting for the site to be up again? Similarly, is there any volume restriction for the same?
Thanks,
Keerthana
For more information about retention policy, I recommend to read doc starting from here.
http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Configureindexstorage