Getting Data In

How to replicate a particular index's indexed data to other set of indexers?

bharadwaja30
Path Finder

We have 2 sets of Indexers in our environment. Set-1 has 29 indexers and Set-2 has 5 indexers.

All the data comes to Set-1 indexers through 16 Heavy Forwarders. This data includes capacity planning data (say with index = cpd). All the capacity data should also be available on Set-2 indexers. Though we can route the capacity planning data directly to the two sets on Indexers, we do not want to do that because it will consume the license twice.

So we want all the data to be indexed in Set-1 indexers. After the data gets indexed, we want to replicate just the data in index=cpd (capacity planning data) to Set-2 indexers. Once the data replicates to Set-2 indexers it should not be indexed again (license concern)

In short, we want to have a copy of a particular index's data (which is available on Set-1 indexers) on Set-2 indexers.

I have gone through splunk docs and splunk answers, but did not find the answer I am looking for.

Could someone help me in getting solution for this issue? Thanks in advance.

0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

HI,

I don't think that's possible to have specific replication settings by index but that would certainly cover that and other more complex replication topologies.
Currently the only possible settings is to replicate or not a index but that's probably not what you wan't to achieve.

I would suggest you to fill a enhancement request for the feature you need.

0 Karma

bharadwaja30
Path Finder

Hi Maraman,

Thanks for responding to my question. Yes, I think you are right. Nowhere in splunk docs did I find how to get this done. May be I need to fill a enhancement request for this feature.

0 Karma

woodcock
Esteemed Legend

This is incorrect. You can control replication on/off on a per-index bases as noted in The indexes.conf repFactor attribute section here:

http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Configurethepeerindexes

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...