<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Skipped searches - Searchable rolling restart or upgrade is in progress in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/553428#M5923</link>
    <description>&lt;P&gt;Thanks once again &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;for answering to my queries. We have 30,000 buckets per indexer (slave/member) in the cluster.&lt;/P&gt;&lt;P&gt;How do I check the below?&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;How many buckets you have in your cluster? Is this 180s enough long time to make all buckets to searchable on another nodes when one node is going down?&lt;/P&gt;&lt;/BLOCKQUOTE&gt;</description>
    <pubDate>Fri, 28 May 2021 00:41:43 GMT</pubDate>
    <dc:creator>arielpconsolaci</dc:creator>
    <dc:date>2021-05-28T00:41:43Z</dc:date>
    <item>
      <title>Skipped searches - Searchable rolling restart or upgrade is in progress</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/552670#M5862</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;&lt;P&gt;Good day. I am experiencing an issue in our cluster where the searches are all skipping with the reason "Searchable rolling restart or upgrade is in progress".&lt;/P&gt;&lt;P&gt;My understanding is that having a searchable rolling restart enabled in the Cluster Manager (indexer) during bundle push minimizes impact to running searches. However, my case is that all the searches are getting skipped regardless.&lt;/P&gt;&lt;P&gt;Seeking advise.&lt;/P&gt;&lt;P&gt;Splunk installed in the SH cluster and Indexer Cluster all has the same version at 8.0.2.&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 24 May 2021 03:45:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/552670#M5862</guid>
      <dc:creator>arielpconsolaci</dc:creator>
      <dc:date>2021-05-24T03:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: Skipped searches - Searchable rolling restart or upgrade is in progress</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/552734#M5865</link>
      <description>How big indexer cluster you have? Is there enough nodes to do this without disruption?</description>
      <pubDate>Mon, 24 May 2021 09:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/552734#M5865</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-05-24T09:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Skipped searches - Searchable rolling restart or upgrade is in progress</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/552759#M5872</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;Thank you for your response. We have 6 search heads and 12 indexers. Enough to avoid such issue.&lt;/P&gt;</description>
      <pubDate>Mon, 24 May 2021 11:47:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/552759#M5872</guid>
      <dc:creator>arielpconsolaci</dc:creator>
      <dc:date>2021-05-24T11:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: Skipped searches - Searchable rolling restart or upgrade is in progress</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/552769#M5873</link>
      <description>And those are in one single site cluster? You probably have read this: &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Indexer/Userollingrestart#Best_practices_for_searchable_rolling_restart" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/Indexer/Userollingrestart#Best_practices_for_searchable_rolling_restart&lt;/A&gt;&lt;BR /&gt;If those are wrongly set the result could be a stuck restart or as you have skipped searches.&lt;BR /&gt;&lt;BR /&gt;Did this works when you are doing RR from command line/GUI without initiate it with apply cluster bundle? If yes then you should check those configurations that they are present to do searchable RR by default also in apply (I haven't try this with apply and I haven't enough big cluster where to test it now).&lt;BR /&gt;&lt;BR /&gt;Also there could be a situation that not all buckets are fulfil SF over cluster (e.g. some buckets in some nodes has already frozen but those replicas are still in one node). In this kind of situation searchable RR cannot do.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Mon, 24 May 2021 12:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/552769#M5873</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-05-24T12:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Skipped searches - Searchable rolling restart or upgrade is in progress</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/552842#M5877</link>
      <description>&lt;P&gt;Appreciate your response&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;. Yes, I've gone through that &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Indexer/Userollingrestart#Best_practices_for_searchable_rolling_restart" target="_self"&gt;document&lt;/A&gt; and the best practice in our cluster is observed below.&lt;/P&gt;&lt;PRE&gt;[clustering]
restart_timeout = 600
rolling_restart = searchable_force
decommission_force_timeout = 180&lt;/PRE&gt;&lt;P&gt;The cluster is in a multi-site cluster.&lt;/P&gt;&lt;P&gt;I am running the indexer apply bundle push via backend and&amp;nbsp; I've observed based from logs in the UI that the searchable rolling restart is running.&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 01:58:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/552842#M5877</guid>
      <dc:creator>arielpconsolaci</dc:creator>
      <dc:date>2021-05-25T01:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Skipped searches - Searchable rolling restart or upgrade is in progress</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/552874#M5881</link>
      <description>&lt;P&gt;How many buckets you have in your cluster? Is this 180s enough long time to make all buckets to searchable on another nodes when one node is going down?&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 06:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/552874#M5881</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-05-25T06:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Skipped searches - Searchable rolling restart or upgrade is in progress</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/553428#M5923</link>
      <description>&lt;P&gt;Thanks once again &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;for answering to my queries. We have 30,000 buckets per indexer (slave/member) in the cluster.&lt;/P&gt;&lt;P&gt;How do I check the below?&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;How many buckets you have in your cluster? Is this 180s enough long time to make all buckets to searchable on another nodes when one node is going down?&lt;/P&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Fri, 28 May 2021 00:41:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/553428#M5923</guid>
      <dc:creator>arielpconsolaci</dc:creator>
      <dc:date>2021-05-28T00:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Skipped searches - Searchable rolling restart or upgrade is in progress</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/553583#M5932</link>
      <description>&lt;P&gt;Basically not so much buckets (expecting that your storage has at least 800 IOPS).&lt;/P&gt;&lt;P&gt;I haven't any idx cluster in my hand now to check the correct strings to get actual service start time, but you could get the estimated down time by this query.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal (component=ServerConfig "My GUID") OR ( component=IndexProcessor "request state change from=RUN to=SHUTDOWN_SIGNALED")
| transaction host startswith="request state change from=RUN to=SHUTDOWN_SIGNALED" endswith="My GUID"
| eval time = tostring(duration,"duration")
| table _time host duration&lt;/LI-CODE&gt;&lt;P&gt;It starts counting from shutdown signal and ends it when splunkd starts again. In real cluster it do a lot of stuff before it's ready for service. You could check those from individual indexer or cm to get actual time.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 20:14:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/553583#M5932</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-05-28T20:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Skipped searches - Searchable rolling restart or upgrade is in progress</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/554577#M6036</link>
      <description>&lt;P&gt;This is working as designed unfortunately&lt;/P&gt;&lt;P&gt;You may wish to vote for &lt;A href="https://ideas.splunk.com/ideas/EID-I-12" target="_blank"&gt;https://ideas.splunk.com/ideas/EID-I-12&lt;/A&gt; Splunk indexing tier searchable rolling restart should allow the scheduler to run jobs as expected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a copy and paste of the idea The title may sound counter-intuitive if you are not familiar with this feature, the current implementation (8.0.1, 7.3.4) of the searchable rolling restart feature at the indexing tier results in the scheduler at the search head level pausing all scheduled jobs until the rolling restart or rolling upgrade completes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Personally I would have preferred the current feature be called "searchable ad-hoc only rolling restart", as per &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Userollingrestart#Disable_deferred_scheduled_searches" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Userollingrestart#Disable_deferred_scheduled_searches&lt;/A&gt; there are settings such as:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;defer_scheduled_searchable_idxc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However this setting is also slightly unclear, what it can do is allow continuously scheduled saved searches to run during a rolling restart, it has no effect on realtime scheduled searches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For those not familiar with the difference, real time scheduling is all alerts, most reports excluding those that are designed to summarize data for summary indexes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Therefore the feature in its current form allows ad-hoc only searching while the indexer cluster is restarting or undergoing an upgrade.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This idea is that the feature allows the scheduler to continue to run searches in a reliable fashion during the rolling restart, this would mean that searchable rolling restart is truly searchable for all search types, not just ad-hoc only searches&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For anyone unfamiliar with continuous and real time scheduling refer to &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Report/Configurethepriorityofscheduledreports" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Report/Configurethepriorityofscheduledreports&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jun 2021 08:02:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/554577#M6036</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2021-06-05T08:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Skipped searches - Searchable rolling restart or upgrade is in progress</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/560724#M6496</link>
      <description>&lt;P&gt;This explains it. Thanks for this!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 02:27:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Skipped-searches-Searchable-rolling-restart-or-upgrade-is-in/m-p/560724#M6496</guid>
      <dc:creator>arielpconsolaci</dc:creator>
      <dc:date>2021-07-26T02:27:01Z</dc:date>
    </item>
  </channel>
</rss>

