Getting Data In

How to replicate a particular index's indexed data to other set of indexers?

bharadwaja30
Explorer

We have 2 sets of Indexers in our environment. Set-1 has 29 indexers and Set-2 has 5 indexers.

All the data comes to Set-1 indexers through 16 Heavy Forwarders. This data includes capacity planning data (say with index = cpd). All the capacity data should also be available on Set-2 indexers. Though we can route the capacity planning data directly to the two sets on Indexers, we do not want to do that because it will consume the license twice.

So we want all the data to be indexed in Set-1 indexers. After the data gets indexed, we want to replicate just the data in index=cpd (capacity planning data) to Set-2 indexers. Once the data replicates to Set-2 indexers it should not be indexed again (license concern)

In short, we want to have a copy of a particular index's data (which is available on Set-1 indexers) on Set-2 indexers.

I have gone through splunk docs and splunk answers, but did not find the answer I am looking for.

Could someone help me in getting solution for this issue? Thanks in advance.

0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

HI,

I don't think that's possible to have specific replication settings by index but that would certainly cover that and other more complex replication topologies.
Currently the only possible settings is to replicate or not a index but that's probably not what you wan't to achieve.

I would suggest you to fill a enhancement request for the feature you need.

0 Karma

bharadwaja30
Explorer

Hi Maraman,

Thanks for responding to my question. Yes, I think you are right. Nowhere in splunk docs did I find how to get this done. May be I need to fill a enhancement request for this feature.

0 Karma

woodcock
Esteemed Legend

This is incorrect. You can control replication on/off on a per-index bases as noted in The indexes.conf repFactor attribute section here:

http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Configurethepeerindexes

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...