Getting Data In

Does index clustering need to be used in order to use Smart Store?

vonsolo29
Explorer

Do you have to use index clustering in order to use Smart Store? We currently have 4 standalone indexers that all UF are sending to and would like to use Smart Store.

0 Karma

MuS
Legend

Hi vonsolo29,

The docs tell you how to enable SmartStore on a standalone indexer https://docs.splunk.com/Documentation/Splunk/latest/Indexer/DeploySmartStorestandalone this means it is possible.

But I highly recommend to read this section of the docs as well https://docs.splunk.com/Documentation/Splunk/latest/Indexer/AboutSmartStore#Choosing_SmartStore when you consider to move to SmartStore.

Hope this helps ...

cheers, MuS

0 Karma

vonsolo29
Explorer

yep i think that makes sense, so similar to how we have it set up today if an indexer goes down we can not search the data on that indexer. With remote storage it will be the same way, each indexer will manage its own buckets locally and remotely.

0 Karma

MuS
Legend

Exactly, only that those buckets can be in a remote S3 storage now instead on a local disk.

0 Karma

vonsolo29
Explorer

Interesting, i was told by our splunk reps that SmartStore does not work with multiple standalone indexers. and we must use clustering

0 Karma

MuS
Legend

Each one of them can use SmartStore for its own storage, but they will not be able to share those SmartStore buckets like the index cluster nodes could - if that makes sense.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...