Deployment Architecture

deploying splunk multisite cluster with 1 indexer per site

vitojij183
Explorer

hi

I wanna deploy multisite cluster with 2 sites, 1 in-branch and another in a datacenter, I have 1 indexer for each site,

I wanna each site have a copy of another site if the one site goes down, but I really dont understand about site replication factor and search factor. can someone please help me to figure out how to deploy this cluster?

 

best regards

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
I think that this is doable by setting local SF + RF = 1 and site_SF+RF: origin:1, total:2
But when you are bringing it up it don't start to working before both nodes are up.
I propose that try to get at least 2 indexer per site to get this working without bigger challenges.

vitojij183
Explorer

another question,

i dont understand this line "But when you are bringing it up it don't start to working before both nodes are up."

can you explain it more ?

thank you

0 Karma

isoutamo
SplunkTrust
SplunkTrust
As you have only one node per site and both sites must have one copies of buckets, then it’s not functional before both sites have one node up and running. Of course you could force it to star manually on cm if needed.
0 Karma

vitojij183
Explorer

thank you for your answer

what happens if I add this configuration on the master node with my architecture?

multisite = true
available_sites = site1,site2
site_replication_factor = origin:1,site1:1,site2:1,total:2
site_search_factor = origin:1,site1:1,site2:1,total:2
replication_factor = 2

 

best regards

0 Karma

isoutamo
SplunkTrust
SplunkTrust
It didn't work as you set replication_factor as 2 and you have only 1 node on site. Also search_factor must be 1.
r. Ismo
Get Updates on the Splunk Community!

Digital Resilience Assessment Launch | How prepared are you for disruption?

Disruption is inevitable. The question is – how prepared are you to handle it? In today’s fast-moving digital ...

Buttercup Games: Further Dashboarding Techniques (Part 2)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Index This | What is the next number in the series? 7,645 5,764 4,576…

February 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...