Getting Data In

What happen when one of peer goes down and the other peer's storage is full?

Takajian
Builder

I am thinking to use data duplication function in clustering environment. I understand there are search factors and replication factors to replicate data. When one of peers goes down, I assume the other peers replicate data according to replication policy ( search factors and replication factors ). My question is what happen when one of peer goes down and the other peer's storage is full?

Tags (1)
0 Karma

Takajian
Builder

I would like to know about replication function. If master node look for peer which have enough disk space or remove oldest replicated buckets and so on.

0 Karma

yannK
Splunk Employee
Splunk Employee

from the forwarder point of view

With a forwarder sending data loadbalanced to a set of indexers, if none of the indexers accepts data (outage, queues full, disk full...), then the forwarder will pause (stop monitoring the files, fill the persistent queues if any, and ultimately drop the non persistent events like udp/tcp/scripts)

0 Karma

Takajian
Builder

Do you know from replication function point of view?

0 Karma

bmacias84
Champion

Do you mean search functionality, indexing, and/or affects to forwarders?

0 Karma

Takajian
Builder

Please let me know if my question is not clear.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...