Getting Data In

Can we add indexers with smaller storage?

ddrillic
Ultra Champion

We are about to add a couple of indexers but they have fewer TBs for storage. Is it ok? How would it work out? They should have about 80% of the existing indexers, storage-wise...

Tags (2)

gjanders
SplunkTrust
SplunkTrust

In addition to somesoni2's comments, how much % disk used do you have on the existing indexers?
While initially new data / replicated data will be added to the new indexers, there are a few scenarios that can trigger a data re-balance which will even the spread of data among the cluster members.

So when you do the calculation, let's say you have 10 nodes of 1024GB each currently (total 10240GB), and you adding 2 800GB nodes.
If your using 9216GB already in the cluster (90%) and you add 2 more then the total is 11840GB available.
So you could end up with 768GB/indexer which would make your new indexers close to the limit before they accept new data...

Obviously the above maths is a very simple example and the data balance is never perfect so you would want some space left for contingency.

0 Karma

somesoni2
SplunkTrust
SplunkTrust

Could you provide little more details about your environment, specifically on Indexer side? Do you use Indexer cluster? Single-site/Multisite? If yes, what are the replication factor and search factor for it?

0 Karma

petercow
Path Finder

Yes, but it's going to make things like clustering problematic.

0 Karma

ddrillic
Ultra Champion

Right, we use an Indexer cluster of 10 nodes where the replication factor and search factor are at 3.

0 Karma

somesoni2
SplunkTrust
SplunkTrust

It is strongly recommended that you provision all peer nodes to use the same amount of disk storage. Saying that it may still work fine with no major issues, as long as new nodes always have sufficient storage to handle incoming data and replicated data. I would setup an alert to monitor disk space on peer node to ensure get alerted before time, in case those low storage peers are near full.

ddrillic
Ultra Champion

Much appreciated @somesoni2

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...