We have the exact same issue: 2 Sites with site_replication_factor = origin:2,total:4 When a site is down (for example for desaster recovery test purposes or due to a datacenter/region outage), the other site starts to replicating everything to match total:4. Splunk even moves data to frozen to get to the point that this replication factor is matched again. So you can lose data due to this behavior ☹️ Is there a possibility to tell splunk that the maximum replication-factor per site must be 2, not 4?
... View more