Splunk Inc.
Recovering pre-indexed data from a shared storage system following a failed indexer

Last updated:

Abstract:

Systems and methods are described for improving data availability and/or resiliency of indexers of a data intake and query system. A data intake and query system can index large amounts of data using one or more indexers. An indexer can store a copy of the data that the indexer is assigned to process in the shared storage system, and a cluster master can track the storage of the data and the indexer assigned to process the data. In the event an indexer fails or is otherwise unable to index data that it has been assigned to index, the cluster master can assign one or more second indexers to process the data. The second indexer can download the data from the shared storage system.

Status:
Grant
Type:

Utility

Filling date:

31 Jan 2020

Issue date:

6 Sep 2022