- Splunk 7.x Quick Start Guide
- James H. Baxter
- 245字
- 2021-06-10 19:04:55
Search factor
When you configure the cluster master node to specify the replication factor, you also designate a search factor. The search factor determines the number of searchable copies of data the indexing cluster maintains. The default value for a search factor is 2, meaning that the cluster maintains two searchable copies of all the data buckets. The search factor must be less than or equal to the replication factor.
The difference between a searchable and a non-searchable copy of a data bucket is that the searchable copies include both the raw data itself and the index files the indexer uses to search the data; a non-searchable copy just contains the raw data alone. Data stored as a non-searchable copy is saved in a form that makes it possible to recreate the index files later, if necessary, but the data won't be immediately searchable otherwise.
The trade-off with the search factor setting is that keeping searchable copies of data takes more disk storage than non-searchable data. The default search factor of 2 is sufficient for most situations, keeping in mind that, if a single node goes down, the cluster master works quickly to create and redistribute searchable copies elsewhere in the cluster.
In summary, the replication factor simply represents the number of copies of the raw data maintained across the indexing tier, and the search factor represents the number of copies of the index files used for searching that data that is maintained.
- Microsoft Dynamics CRM Customization Essentials
- Deep Learning Quick Reference
- Mastercam 2017數控加工自動編程經典實例(第4版)
- 計算機應用復習與練習
- TIBCO Spotfire:A Comprehensive Primer(Second Edition)
- Mastering Salesforce CRM Administration
- PyTorch深度學習實戰
- Associations and Correlations
- 人工智能趣味入門:光環板程序設計
- Ruby on Rails敏捷開發最佳實踐
- 云計算和大數據的應用
- Ansible 2 Cloud Automation Cookbook
- 大數據案例精析
- 中國戰略性新興產業研究與發展·數控系統
- 天才與算法:人腦與AI的數學思維