Splunk IT Service Intelligence

How do I maintain / what do I backup in my Indexer clustering in order to keep my indexer data intact "just in case"?

SamHTexas
Builder

How do I maintain my indexer clustering to keep Indexer data intact for disaster recovery sake. Thank u 

Labels (1)
Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

On the clustered indexers, the data you want to keep are :

- the splunk configurations ( SPLUNK_HOME/etc/ usually pushed from your cluster-master), so you could always repush them if you rebuild a new indexer.

- the copies of the buckets in the indexes. Those buckets are replicated across indexers, based on your replication factor RF.

By example with RF =3 , there are 3 copies of each buckets on different peer. So if you lose up to 2 indexers, the data will still be there on the remaining. (who will replicate to meet the RF. You want to bring new indexers to replace them and let the replication occur and optimize the spreading)

If you do not want to just rely on the replication, you can always do additional backups of your indexes folders (by default in SPLUNK_HOME/var/lib/splunk, but you may have custom path, check your indexes.conf homepath and coldpath to figure where)

here is the guide to backup your indexes 
https://docs.splunk.com/Documentation/Splunk/8.2.2/Indexer/Backupindexeddata

Remarks :


- doing a backup of live hot buckets (while splunk is on), is not bueno, there is a risk that those files are not in good state when you try to restore them, as they were being written to. You will see in the doc a method to force hot buckets to roll to warm, just before doing a file system backup. (then ignore the new hot buckets during the backup)

- as you are on an indexer cluster, you may have several copies of the same bucket, so your backup will be larger. But there is not easy way to strategize which copy to save to save backup space.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...