Getting Data In

When initiating an indexer cluster, why is the restart of indexers so slow?

ameslet
Explorer

Hi,

I have two indexers linked to a master node. Since I have linked both indexers to the master node, it takes forever to restart both of them. Does anyone know what is slowing the restart down down so much for my indexers and what can I do to fix it?

Thanks in advance,

Alex

0 Karma
1 Solution

woodcock
Esteemed Legend

Because every Indexer has to make copies of large portions of ALL EXISTING DATA and send copies to other indexers. This means each indexer is busy both sending and receiving a huge number of buckets.

View solution in original post

0 Karma

ddrillic
Ultra Champion

Alex, you can track the progress via the Indexer Clustering console on the replication server.

alt text

The progress depends on the Replication Factor and the Search Factor.

woodcock
Esteemed Legend

Because every Indexer has to make copies of large portions of ALL EXISTING DATA and send copies to other indexers. This means each indexer is busy both sending and receiving a huge number of buckets.

0 Karma

ameslet
Explorer

Okay I see. Is there any way to select the data every indexer send to the the others ?
For example, to tell the indexer to just make copies of data from the last month and send it to the other indexer.
I have data from a year ago in both of my indexers and I don't need them to copy so much of it.

0 Karma

woodcock
Esteemed Legend

I am not aware are any way to "selectively/partially" cluster index data. But you can set smaller retention periods on your index so that it gets deleted sooner. This way there is less to copy. Also, this problem will only really be a problem the first time that you start an indexer after bringing it into the cluster. Once the initial copies are done, later restarts should be much quicker.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...