Deployment Architecture

deploying splunk multisite cluster with 1 indexer per site

vitojij183
Explorer

hi

I wanna deploy multisite cluster with 2 sites, 1 in-branch and another in a datacenter, I have 1 indexer for each site,

I wanna each site have a copy of another site if the one site goes down, but I really dont understand about site replication factor and search factor. can someone please help me to figure out how to deploy this cluster?

 

best regards

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
I think that this is doable by setting local SF + RF = 1 and site_SF+RF: origin:1, total:2
But when you are bringing it up it don't start to working before both nodes are up.
I propose that try to get at least 2 indexer per site to get this working without bigger challenges.

vitojij183
Explorer

another question,

i dont understand this line "But when you are bringing it up it don't start to working before both nodes are up."

can you explain it more ?

thank you

0 Karma

isoutamo
SplunkTrust
SplunkTrust
As you have only one node per site and both sites must have one copies of buckets, then it’s not functional before both sites have one node up and running. Of course you could force it to star manually on cm if needed.
0 Karma

vitojij183
Explorer

thank you for your answer

what happens if I add this configuration on the master node with my architecture?

multisite = true
available_sites = site1,site2
site_replication_factor = origin:1,site1:1,site2:1,total:2
site_search_factor = origin:1,site1:1,site2:1,total:2
replication_factor = 2

 

best regards

0 Karma

isoutamo
SplunkTrust
SplunkTrust
It didn't work as you set replication_factor as 2 and you have only 1 node on site. Also search_factor must be 1.
r. Ismo
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...