Deployment Architecture

Backup of indexed data in cluster with two nodes and replication factor = 2

mas
Path Finder

Hi,

we have a multisite indexers cluster with two nodes and replication factor = 2. All instances are running Splunk 6.2. In the official documentation we read that it is not possible to back up just the data on a single node, since there's no certainty that a single node contains all the data in the cluster.

I suspect that this is not true in our scenario, where all data are replicated to both nodes (replication factor = total number of peers). Am I right? Can we backup data from one node (snapshot backup) and be sure that all data has been saved?

0 Karma
1 Solution

mahamed_splunk
Splunk Employee
Splunk Employee

If there are only 2 nodes and RF = 2 and the cluster met all policies (the dashboard is green), then you can take back up from single node.

View solution in original post

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

If there are only 2 nodes and RF = 2 and the cluster met all policies (the dashboard is green), then you can take back up from single node.

0 Karma

mas
Path Finder

Thank you.

It would be nice to be able to check the cluster status before starting the backup job, raising a warning if it is not consistent. I think the only way to automate this check would be to run "bin/splunk show cluster-status --verbose" and check for "Replication factor met" and "Search factor met", but this command is available only on master node, while the check should be executed by the backup agent running on one of the peers. In addition, there would be an authentication request from Splunk daemon.

As a result, I think it is not possible to automate this check in a simple way.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...