Getting Data In

How to replicate a particular index's indexed data to other set of indexers?

bharadwaja30
Path Finder

We have 2 sets of Indexers in our environment. Set-1 has 29 indexers and Set-2 has 5 indexers.

All the data comes to Set-1 indexers through 16 Heavy Forwarders. This data includes capacity planning data (say with index = cpd). All the capacity data should also be available on Set-2 indexers. Though we can route the capacity planning data directly to the two sets on Indexers, we do not want to do that because it will consume the license twice.

So we want all the data to be indexed in Set-1 indexers. After the data gets indexed, we want to replicate just the data in index=cpd (capacity planning data) to Set-2 indexers. Once the data replicates to Set-2 indexers it should not be indexed again (license concern)

In short, we want to have a copy of a particular index's data (which is available on Set-1 indexers) on Set-2 indexers.

I have gone through splunk docs and splunk answers, but did not find the answer I am looking for.

Could someone help me in getting solution for this issue? Thanks in advance.

0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

HI,

I don't think that's possible to have specific replication settings by index but that would certainly cover that and other more complex replication topologies.
Currently the only possible settings is to replicate or not a index but that's probably not what you wan't to achieve.

I would suggest you to fill a enhancement request for the feature you need.

0 Karma

bharadwaja30
Path Finder

Hi Maraman,

Thanks for responding to my question. Yes, I think you are right. Nowhere in splunk docs did I find how to get this done. May be I need to fill a enhancement request for this feature.

0 Karma

woodcock
Esteemed Legend

This is incorrect. You can control replication on/off on a per-index bases as noted in The indexes.conf repFactor attribute section here:

http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Configurethepeerindexes

Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...