Getting Data In

What are best practices on setting the replication factor for X number of indexers in an indexer cluster?

dhavamanis
Builder

Need your help,

We are trying to increase the number of indexer nodes in the indexer cluster for max availability approach. Can you please share the best Splunk replication factor vs number of indexer nodes? Because we want to use minimal storage and all time data availability for search even if one or two nodes went down in the indexer pool.

0 Karma
1 Solution

somesoni2
Revered Legend

IMK, the Replication factor is set uses only criteria which depends on "How many node failure you can tolerate without data loss".
So,

Replication Factor = No of allowed Indexer failure +1 

If you've 4 indexers and want all data to available even with 2 nodes failed then you need replication factor of 3 and so on.

See this for more information

http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Thereplicationfactor#Replication_factor_an...

View solution in original post

somesoni2
Revered Legend

IMK, the Replication factor is set uses only criteria which depends on "How many node failure you can tolerate without data loss".
So,

Replication Factor = No of allowed Indexer failure +1 

If you've 4 indexers and want all data to available even with 2 nodes failed then you need replication factor of 3 and so on.

See this for more information

http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Thereplicationfactor#Replication_factor_an...

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...