Hey Splunk Friends, I currently have 32 indexes spread across 2 peers managed by 1 master. The total space for these indexes has now reached just under 3,000Gb (one of the indexes alone is 1,486Gb). We don't really have any performance issues at present, but when the Splunk machines get restarted for any reason, it does take some time for the Indexes to catch up (Replication Factor, Search, etc). On the odd occasion, if there has been an issue which lasted longer, it has caused us to see bucket issues. My question, is 32 indexes (3000Gb) too much for one cluster (two peers)? If so, should I create another cluster? Or add additional peers?
... View more