Deployment Architecture

Would Data Rebalance of Primary Cluster Buckets Work on RepFactor=1?

joshualemoine
Path Finder

We have a 51-Node Index Cluster where we do not replicate Index bucket copies. We only have a primary copy of the buckets (so actually no "copy", just a single instance of each bucket on a single Indexer), and we use the CM/IDX Cluster for it's management capabilities. Our repfactor=1.

Will data rebalancing, for the sole purpose of getting those single primary buckets that are amassed on earlier built Indexers moved between newer built Indexers, work to average out storage across the Cluster? 

I've heard from PS that it will, but have heard from other Splunk Admins that it will only work with "copies" of bucket data, and since we don't have "copies", but single instances of primary buckets, it will not work.

We are not yet using SmartStore. We have over 600TB of storage between hot/warm/cold. All of it is through GCP and is attached/mounted to the VMs. We would probably want to do a searchable-rebalance if it would even work on our cluster.

Thanks in advance!!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...