Getting Data In

How to exclude one or more cluster peers from the index replication target list?

rbal_splunk
Splunk Employee
Splunk Employee

As the Cluster Deployments are reaching maturity, we are planning to add a new Cluster Peer/Indexer to the existing Cluster Master, especially when currently available clustered indexers reach Disk Storage Capacity. When the New Indexers are added, forwarders are configured to stop sending the data to old indexers, and data is INDEXED on the newly added Cluster Peer. Unfortunately, data is still getting replicated to the Legacy Cluster Peer which results in unintended consequences and causes the disk space to fill up on clustered indexers.

Ideally, we would prefer if the Cluster Master could calculate the available disk on each indexer and make informed decisions during replication, and not replicate data if some peer is close to Disk Storage Capacity. Otherwise, Splunk should at least provide a Capability to manually exclude some peers from replication, either from the UI or using a REST call.

1 Solution

rbal_splunk
Splunk Employee
Splunk Employee

This requirement is being tracked by the following Bug's

SPL-97395:Indexer clustering supportability issues that need to be fixed.
SPL-92136:AASAIWT exclude one or more cluster peers from the index replication target list

Please watch future Splunk release notes for update on these Bugs.

View solution in original post

rbal_splunk
Splunk Employee
Splunk Employee

This requirement is being tracked by the following Bug's

SPL-97395:Indexer clustering supportability issues that need to be fixed.
SPL-92136:AASAIWT exclude one or more cluster peers from the index replication target list

Please watch future Splunk release notes for update on these Bugs.

bschaefer
Splunk Employee
Splunk Employee

I have a few requests for being able to have site 1 replicate to site 2 while site 2 replicates nothing ("cold" DR).

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...