Splunk Enterprise

Replication factor = 1 and maintenance mode does not do much in this situation, correct?

PickleRick
SplunkTrust
SplunkTrust

While preparing to upgrade of an indexer cluster with RF=1 I'm wondering what's the effective behaviour of a cluster in maintenance mode with this RF.

If an indexer goes down because of the upgrade activity and restart, there is no data to replicate to other nodes anyway so no fixups should occur.

So maintenance mode does not really do much in this case, am I right?

Labels (2)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @PickleRick,

what do you mean with "RF=1"? in this way you haven't HA!

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Yes, I'm fully aware of that. That's why I wrote that there's nothing to replicate in case one indexer is down 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @PickleRick,

in this case, you also could not use an Indexer Cluster, so you have one server less.

and you don't need maintenence mode.

Ciao.

Giuseppe

PickleRick
SplunkTrust
SplunkTrust

Well, I'll be able to use the cluster, it's just that I'll be getting incomplete results from searches because of partial data unavailability. Been there, done that, got the T-shirt 😉

It could as well be just a simple distributed search setup but I have those indexers clustered so the buckets can be rebalanced manually in need. Don't ask, I "inherited" it that way.

But I was simply wondering whether I was properly interpreting the maintenance mode effect. It seems I do - no data to replicate thus no unnecessary bucket fixup.

Thanks.

Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...