Getting Data In

Data Archiving and Clusters

mcclainsm47
Engager

I have a clustered Splunk set up with 3 indexing peers and a replication factor of 3. There are a couple of indexes that need to be archived when frozen instead of deleted, but I want to avoid having duplicate copies. The documentation mentions: "You cannot solve this problem by archiving just the data on a single node, since there's no certainty that a single node contains all the data in the cluster."

However, I'm thinking that only applies when you've got more indexers than your search factor. Since the number of indexers = replication factor, each server should have all the buckets and thus I would be able to just keep buckets from one of them. Am I missing something?

Tags (2)
1 Solution

mahamed_splunk
Splunk Employee
Splunk Employee

Yes, at the time of archiving if the cluster master dashboard is green, then you can take backup from a single server.

View solution in original post

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

Yes, at the time of archiving if the cluster master dashboard is green, then you can take backup from a single server.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...