Deployment Architecture

Would Data Rebalance of Primary Cluster Buckets Work on RepFactor=1?

joshualemoine
Path Finder

We have a 51-Node Index Cluster where we do not replicate Index bucket copies. We only have a primary copy of the buckets (so actually no "copy", just a single instance of each bucket on a single Indexer), and we use the CM/IDX Cluster for it's management capabilities. Our repfactor=1.

Will data rebalancing, for the sole purpose of getting those single primary buckets that are amassed on earlier built Indexers moved between newer built Indexers, work to average out storage across the Cluster? 

I've heard from PS that it will, but have heard from other Splunk Admins that it will only work with "copies" of bucket data, and since we don't have "copies", but single instances of primary buckets, it will not work.

We are not yet using SmartStore. We have over 600TB of storage between hot/warm/cold. All of it is through GCP and is attached/mounted to the VMs. We would probably want to do a searchable-rebalance if it would even work on our cluster.

Thanks in advance!!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...