Deployment Architecture

indexer replication

dkr3500
Path Finder

I stood up a new set of indexers this weekend and set my RF=2 and SF=1 on the CM with the hope that the old indexers will replicate the data and populate the new set of indexers (I'm going to eventually decom the old indexers).

However, that doesn't seem to be working.  All the peers are up and running, and UFs are sending data correctly via indexer_discovery...but the data isn't being replicated.  My question is, why aren't my indexes (other than these native ones) showing up here on the CM? (Settings > Indexer clustering > Indexes tab:

Only native indexes are showing up on cluster master.Only native indexes are showing up on cluster master.

Labels (1)
0 Karma
1 Solution

dkr3500
Path Finder

@s2_splunk thanks for following-up on this post.

Splunk doc: https://docs.splunk.com/Documentation/Splunk/8.1.3/Indexer/Migratenon-clusteredindexerstoaclusterede...

I needed to add:

repFactor = auto

under each [index_name] stanza on my cluster master's indexes.conf that gets pushed out to the peer nodes (indexers).

Once I updated indexes.conf, and applied the latest bundle on the CM (/opt/splunk/bin/splunk apply cluster-bundle --answer-yes), it started to replicated the custom indexes.

Important note: don't updated all indexes and push out the new cluster bundle at once, it its too much for the CM...update one index at a time and apply the cluster bundle.

View solution in original post

0 Karma

dkr3500
Path Finder

@s2_splunk thanks for following-up on this post.

Splunk doc: https://docs.splunk.com/Documentation/Splunk/8.1.3/Indexer/Migratenon-clusteredindexerstoaclusterede...

I needed to add:

repFactor = auto

under each [index_name] stanza on my cluster master's indexes.conf that gets pushed out to the peer nodes (indexers).

Once I updated indexes.conf, and applied the latest bundle on the CM (/opt/splunk/bin/splunk apply cluster-bundle --answer-yes), it started to replicated the custom indexes.

Important note: don't updated all indexes and push out the new cluster bundle at once, it its too much for the CM...update one index at a time and apply the cluster bundle.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

What did your deployment look like before, was it already a cluster, albeit a smaller one?

If you did not have a cluster before, your existing data will sit in standalone buckets and will not replicate by default. Also, when using clustering, all peer definitions (indexes.conf) is done on the CM (master-apps) and bundle-pushed to the peers.  This is how the CM knows about indexes in the cluster.

Need to understand a bit better where you started from to be able to help.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...