Splunk Enterprise

Replication factor = 1 and maintenance mode does not do much in this situation, correct?

PickleRick
SplunkTrust
SplunkTrust

While preparing to upgrade of an indexer cluster with RF=1 I'm wondering what's the effective behaviour of a cluster in maintenance mode with this RF.

If an indexer goes down because of the upgrade activity and restart, there is no data to replicate to other nodes anyway so no fixups should occur.

So maintenance mode does not really do much in this case, am I right?

Labels (2)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @PickleRick,

what do you mean with "RF=1"? in this way you haven't HA!

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Yes, I'm fully aware of that. That's why I wrote that there's nothing to replicate in case one indexer is down 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @PickleRick,

in this case, you also could not use an Indexer Cluster, so you have one server less.

and you don't need maintenence mode.

Ciao.

Giuseppe

PickleRick
SplunkTrust
SplunkTrust

Well, I'll be able to use the cluster, it's just that I'll be getting incomplete results from searches because of partial data unavailability. Been there, done that, got the T-shirt 😉

It could as well be just a simple distributed search setup but I have those indexers clustered so the buckets can be rebalanced manually in need. Don't ask, I "inherited" it that way.

But I was simply wondering whether I was properly interpreting the maintenance mode effect. It seems I do - no data to replicate thus no unnecessary bucket fixup.

Thanks.

Get Updates on the Splunk Community!

New This Month - Splunk Observability updates and improvements for faster ...

What’s New? This month, we’re delivering several enhancements across Splunk Observability Cloud for faster and ...

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...