Deployment Architecture

In clustered env, How SH know which indexer is holding the primary bucket or searchable bucket of an index?

poornam
Explorer

In a cluster environment (50+ nodes), how the search head aware of which indexer(s) (search peer) to connect for searchable buckets of an index?

Will cluster master distribute the state of index and indexer to all its clients (SH)? What will if clust master goes down for a day, in this case?

0 Karma
1 Solution

poornam
Explorer

@Skalli, the question is not about what will happen when the master goes down.

The question is, how the search head aware of which indexer(s) (search peer) to connect for searchable buckets of an index, irrespective of cluster master availablity?

View solution in original post

0 Karma

poornam
Explorer

@Skalli, the question is not about what will happen when the master goes down.

The question is, how the search head aware of which indexer(s) (search peer) to connect for searchable buckets of an index, irrespective of cluster master availablity?

0 Karma

skalliger
SplunkTrust
SplunkTrust

Read the article. A SH sends its searches to all of the indexers in a cluster. The one with the data sends the data back. Basically, the cluster continues to work like it did when the master was last available.

0 Karma

poornam
Explorer

Thanks for lead.

The below article gave clear details about distributed search and generation id.
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Bucketsandclusters.

0 Karma

skalliger
SplunkTrust
SplunkTrust

This question and kind of similar questions have beend asked quite a lot.
The cluster will continue to work as long as no other peers are going down, to give you a short answer.

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Whathappenswhenamasternodegoesdown

Skalli

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...