As part of setting up an indexer cluster, you specify the number of copies of data that you want the cluster to maintain. How can I tell how many copies of unique warm buckets were actually replicated across the indexers cluster?
Use this search:
| dbinspect index=* splunk_server=idx*
| search state=warm
| stats count, list(splunk_server) by bucketId
Credit to Guilhem Marchand and Ivan Canes
Use this search:
| dbinspect index=* splunk_server=idx*
| search state=warm
| stats count, list(splunk_server) by bucketId
Credit to Guilhem Marchand and Ivan Canes