Does anyone have experience with index clusters that only contain two indexers? In splunk docs, and in most other forums, the only examples of clusters contain at least three nodes. But shouldn't it function with only two indexers as well? What would be the potential disadvantages, besides less redundancy and reliability?
The default replication factor is three, so all the examples tend to show at least 3 indexers. However, AFAIK there is no restriction: you can have an index cluster with only 2 search peers (indexers). Just be sure to set the replication factor and search factor appropriately.
IMO, the only disadvantage (besides the ones you mention) would be: you must have a search head and a cluster master to complete your indexer cluster. So only half of your assets are actually indexing. I think you would get more for your money if you had a greater number of indexers. OTOH, you may have an initial installation with 2 indexers and plans to grow...
Regarding the number of indexers, or peer nodes, the only requirement is that you have at least as many as the replication factor. For details, see:
Great. Thanks!
The default replication factor is three, so all the examples tend to show at least 3 indexers. However, AFAIK there is no restriction: you can have an index cluster with only 2 search peers (indexers). Just be sure to set the replication factor and search factor appropriately.
IMO, the only disadvantage (besides the ones you mention) would be: you must have a search head and a cluster master to complete your indexer cluster. So only half of your assets are actually indexing. I think you would get more for your money if you had a greater number of indexers. OTOH, you may have an initial installation with 2 indexers and plans to grow...
Ok, great! It is good to know that this will function before the configuration begins, as I only have a production environment available. Hopefully the plan is to grow the number of indexers eventually. Thank you for answering so quickly!