Deployment Architecture

Does a replication factor of three make sense?

ddrillic
Ultra Champion

Our eight indexers are under enormous stress and I wonder whether the replication factor of three makes any sense. Since it's a major design consideration, what do you think? Is there a way to quantity the risk? to assess the effectiveness of replication factor of 1,2 or 3?

Ok, Hadoop does 3 by default within Hadoop, by it's also being questioned quite a bit...

Tags (2)
0 Karma
1 Solution

kmorris_splunk
Splunk Employee
Splunk Employee

It is really based on your tolerance for how many indexers you can lose while still maintaining copies of all your data. A Replication Factor of 3 means you can sustain a loss of 2 indexers and still have access to all of your data.

It does become a trade-off between how many indexers you can tolerate losing and the storage costs associated with each additional copy.

View solution in original post

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

It is really based on your tolerance for how many indexers you can lose while still maintaining copies of all your data. A Replication Factor of 3 means you can sustain a loss of 2 indexers and still have access to all of your data.

It does become a trade-off between how many indexers you can tolerate losing and the storage costs associated with each additional copy.

0 Karma

ddrillic
Ultra Champion

Interesting thing - it seems to me that Replication Factor of 3 puts a huge strain on our system which can cause 2 indexers to go down at the current state. With Replication Factor of 2, we'll probably be very stable for now.

The other aspect is the nature of the data - in our case, not having all the data during a 2 indexers crash, is probably acceptable.

0 Karma

ddrillic
Ultra Champion

Much appreciated.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...