Splunk Enterprise

Replication factor = 1 and maintenance mode does not do much in this situation, correct?

PickleRick
SplunkTrust
SplunkTrust

While preparing to upgrade of an indexer cluster with RF=1 I'm wondering what's the effective behaviour of a cluster in maintenance mode with this RF.

If an indexer goes down because of the upgrade activity and restart, there is no data to replicate to other nodes anyway so no fixups should occur.

So maintenance mode does not really do much in this case, am I right?

Labels (2)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @PickleRick,

what do you mean with "RF=1"? in this way you haven't HA!

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Yes, I'm fully aware of that. That's why I wrote that there's nothing to replicate in case one indexer is down 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @PickleRick,

in this case, you also could not use an Indexer Cluster, so you have one server less.

and you don't need maintenence mode.

Ciao.

Giuseppe

PickleRick
SplunkTrust
SplunkTrust

Well, I'll be able to use the cluster, it's just that I'll be getting incomplete results from searches because of partial data unavailability. Been there, done that, got the T-shirt 😉

It could as well be just a simple distributed search setup but I have those indexers clustered so the buckets can be rebalanced manually in need. Don't ask, I "inherited" it that way.

But I was simply wondering whether I was properly interpreting the maintenance mode effect. It seems I do - no data to replicate thus no unnecessary bucket fixup.

Thanks.

Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques

Hello! We are excited to kick off a new series of blogs from SplunkTrust member ITWhisperer, who demonstrates ...

Message Parsing in SOCK

Introduction This blog post is part of an ongoing series on SOCK enablement. In this blog post, I will write ...

Exploring the OpenTelemetry Collector’s Kubernetes annotation-based discovery

We’ve already explored a few topics around observability in a Kubernetes environment -- Common Failures in a ...