Getting Data In

How to exclude one or more cluster peers from the index replication target list?

rbal_splunk
Splunk Employee
Splunk Employee

As the Cluster Deployments are reaching maturity, we are planning to add a new Cluster Peer/Indexer to the existing Cluster Master, especially when currently available clustered indexers reach Disk Storage Capacity. When the New Indexers are added, forwarders are configured to stop sending the data to old indexers, and data is INDEXED on the newly added Cluster Peer. Unfortunately, data is still getting replicated to the Legacy Cluster Peer which results in unintended consequences and causes the disk space to fill up on clustered indexers.

Ideally, we would prefer if the Cluster Master could calculate the available disk on each indexer and make informed decisions during replication, and not replicate data if some peer is close to Disk Storage Capacity. Otherwise, Splunk should at least provide a Capability to manually exclude some peers from replication, either from the UI or using a REST call.

1 Solution

rbal_splunk
Splunk Employee
Splunk Employee

This requirement is being tracked by the following Bug's

SPL-97395:Indexer clustering supportability issues that need to be fixed.
SPL-92136:AASAIWT exclude one or more cluster peers from the index replication target list

Please watch future Splunk release notes for update on these Bugs.

View solution in original post

rbal_splunk
Splunk Employee
Splunk Employee

This requirement is being tracked by the following Bug's

SPL-97395:Indexer clustering supportability issues that need to be fixed.
SPL-92136:AASAIWT exclude one or more cluster peers from the index replication target list

Please watch future Splunk release notes for update on these Bugs.

bschaefer
Splunk Employee
Splunk Employee

I have a few requests for being able to have site 1 replicate to site 2 while site 2 replicates nothing ("cold" DR).

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...