We are receiving replication failures several times a day between our searchhead and various indexers. From what I understand in distsearch.conf you can blacklist certain data from being replicated. Currently, we have over 100 jobs that run at various points throughout the night. Where can I start looking at within the jobs to see what I am able to blacklist? From what I understand, if a job only uses a specific indexer or search peer, we can tell that job to only replicate the searches needed to that specific search peer. Am I on track here? I am sure there is a lot of other data we can remove from the replication bundles as well.
What's in the bundle?
http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Whatsearchheadssend
blacklisting / whitelisting files in the bundle
http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Limittheknowledgebundlesize
Limiting the search peers (indexers) that your search runs on
http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Distributedsearchgroups
What's in the bundle?
http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Whatsearchheadssend
blacklisting / whitelisting files in the bundle
http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Limittheknowledgebundlesize
Limiting the search peers (indexers) that your search runs on
http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Distributedsearchgroups
I am having the same issues in conjunction with Indexer timeouts. Does anyone have any input for this question? I'm extremely interested.