Getting Data In

What happen when one of peer goes down and the other peer's storage is full?

Takajian
Builder

I am thinking to use data duplication function in clustering environment. I understand there are search factors and replication factors to replicate data. When one of peers goes down, I assume the other peers replicate data according to replication policy ( search factors and replication factors ). My question is what happen when one of peer goes down and the other peer's storage is full?

Tags (1)
0 Karma

Takajian
Builder

I would like to know about replication function. If master node look for peer which have enough disk space or remove oldest replicated buckets and so on.

0 Karma

yannK
Splunk Employee
Splunk Employee

from the forwarder point of view

With a forwarder sending data loadbalanced to a set of indexers, if none of the indexers accepts data (outage, queues full, disk full...), then the forwarder will pause (stop monitoring the files, fill the persistent queues if any, and ultimately drop the non persistent events like udp/tcp/scripts)

0 Karma

Takajian
Builder

Do you know from replication function point of view?

0 Karma

bmacias84
Champion

Do you mean search functionality, indexing, and/or affects to forwarders?

0 Karma

Takajian
Builder

Please let me know if my question is not clear.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...