Deployment Architecture

Would Data Rebalance of Primary Cluster Buckets Work on RepFactor=1?

joshualemoine
Path Finder

We have a 51-Node Index Cluster where we do not replicate Index bucket copies. We only have a primary copy of the buckets (so actually no "copy", just a single instance of each bucket on a single Indexer), and we use the CM/IDX Cluster for it's management capabilities. Our repfactor=1.

Will data rebalancing, for the sole purpose of getting those single primary buckets that are amassed on earlier built Indexers moved between newer built Indexers, work to average out storage across the Cluster? 

I've heard from PS that it will, but have heard from other Splunk Admins that it will only work with "copies" of bucket data, and since we don't have "copies", but single instances of primary buckets, it will not work.

We are not yet using SmartStore. We have over 600TB of storage between hot/warm/cold. All of it is through GCP and is attached/mounted to the VMs. We would probably want to do a searchable-rebalance if it would even work on our cluster.

Thanks in advance!!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...