Deployment Architecture

How to stop site replication when using multisite cluster? (just only need local site replication)

hkhat5
New Member

Dear all,

I have site1 and site2 with multisite cluster on.
However, i just only want to replicate the data within local site only.

What and how to configure that setup?

Thanks
Kelvin

Tags (2)
0 Karma

dxu_splunk
Splunk Employee
Splunk Employee

you can set site_replication_factor and site_search_factor's origin:N and total:N to be the same.
for example:

site_replication_factor = origin:2, total:2
site_search_factor = origin:1, total:1

hkhat5
New Member
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Although, I do believe that if one site doesn't have enough servers, it will try to replicate to the other. Maybe you want this, maybe you don't.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

This is a better answer than mine.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I don't understand what you're asking for. Why are you using multi-site clustering in the first place? Why don't you just create two separate clusters?

0 Karma

hkhat5
New Member

gkanapathy, thanks for your reply.

Just like you said, create 2 two separate clusters.
Can it control by single master node?
Also, can it search all the result with one search head?

Thanks

Kelvin

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You can search both with one search head, but you need two masters, one for each cluster.

0 Karma

hkhat5
New Member

Do you mean that install external search head just outside the 2 clusters?
Thanks

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...