Deployment Architecture

deploying splunk multisite cluster with 1 indexer per site

vitojij183
Explorer

hi

I wanna deploy multisite cluster with 2 sites, 1 in-branch and another in a datacenter, I have 1 indexer for each site,

I wanna each site have a copy of another site if the one site goes down, but I really dont understand about site replication factor and search factor. can someone please help me to figure out how to deploy this cluster?

 

best regards

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
I think that this is doable by setting local SF + RF = 1 and site_SF+RF: origin:1, total:2
But when you are bringing it up it don't start to working before both nodes are up.
I propose that try to get at least 2 indexer per site to get this working without bigger challenges.

vitojij183
Explorer

another question,

i dont understand this line "But when you are bringing it up it don't start to working before both nodes are up."

can you explain it more ?

thank you

0 Karma

isoutamo
SplunkTrust
SplunkTrust
As you have only one node per site and both sites must have one copies of buckets, then it’s not functional before both sites have one node up and running. Of course you could force it to star manually on cm if needed.
0 Karma

vitojij183
Explorer

thank you for your answer

what happens if I add this configuration on the master node with my architecture?

multisite = true
available_sites = site1,site2
site_replication_factor = origin:1,site1:1,site2:1,total:2
site_search_factor = origin:1,site1:1,site2:1,total:2
replication_factor = 2

 

best regards

0 Karma

isoutamo
SplunkTrust
SplunkTrust
It didn't work as you set replication_factor as 2 and you have only 1 node on site. Also search_factor must be 1.
r. Ismo
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...