<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does my search head only sometimes see a peer? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297221#M11251</link>
    <description>&lt;P&gt;Hi Duke_Splunk_admins, &lt;/P&gt;

&lt;P&gt;During each search the list of search peers will be involved in the search action. Since you are aware of one peer is down you can remove from your indexer cluster till the time server backup. &lt;/P&gt;

&lt;P&gt;Follow the below steps to remove the peer, (Read the notes before perform any, make sure master is in maintenance mode )&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.2/Indexer/Removepeerfrommasterlist" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.2/Indexer/Removepeerfrommasterlist&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Best practice to take the search peer offline, &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/Indexer/Takeapeeroffline" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.2/Indexer/Takeapeeroffline&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Hope this will helps you....&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 15:25:03 GMT</pubDate>
    <dc:creator>vasanthmss</dc:creator>
    <dc:date>2020-09-29T15:25:03Z</dc:date>
    <item>
      <title>Why does my search head only sometimes see a peer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297220#M11250</link>
      <description>&lt;P&gt;I have an index cluster where one peer is down (as in we're talking to Cisco).  When I run a Splunk list search-server on one of our search-heads, sometimes it shows the IP of the down peer as &lt;STRONG&gt;Down&lt;/STRONG&gt;, and other times it just doesn't list the downed peer at all.&lt;BR /&gt;
I have an alert set up which monitors the results of the command that is sent to my SOC so they know when there is a connection problem, so I'm getting a lot of tickets. Why does the search-head see the peer sometimes and not others? How do I stop it? The box is entirely unreachable.&lt;BR /&gt;
The setup is standard, where the search-head connects to the cluster master, and the indexer is still listed on the master because it hasn't been long enough for it to age out.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 15:49:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297220#M11250</guid>
      <dc:creator>duke_splunk_adm</dc:creator>
      <dc:date>2017-08-22T15:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my search head only sometimes see a peer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297221#M11251</link>
      <description>&lt;P&gt;Hi Duke_Splunk_admins, &lt;/P&gt;

&lt;P&gt;During each search the list of search peers will be involved in the search action. Since you are aware of one peer is down you can remove from your indexer cluster till the time server backup. &lt;/P&gt;

&lt;P&gt;Follow the below steps to remove the peer, (Read the notes before perform any, make sure master is in maintenance mode )&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.2/Indexer/Removepeerfrommasterlist" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.2/Indexer/Removepeerfrommasterlist&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Best practice to take the search peer offline, &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/Indexer/Takeapeeroffline" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.2/Indexer/Takeapeeroffline&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Hope this will helps you....&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:25:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297221#M11251</guid>
      <dc:creator>vasanthmss</dc:creator>
      <dc:date>2020-09-29T15:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my search head only sometimes see a peer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297222#M11252</link>
      <description>&lt;P&gt;That's not exactly what I'm asking, although it is very helpful.&lt;BR /&gt;
The behaviour is is: I have 4 peers, one of which is down.  When I do a splunk list search-server sometimes I see 3 peers, all up, and sometimes I see 4, one of which is marked Down. &lt;BR /&gt;
This throws off the monitoring system, as it appears to be flapping.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 16:47:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297222#M11252</guid>
      <dc:creator>duke_splunk_adm</dc:creator>
      <dc:date>2017-08-23T16:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my search head only sometimes see a peer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297223#M11253</link>
      <description>&lt;P&gt;Have you check your distsearch.conf? &lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 20:55:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297223#M11253</guid>
      <dc:creator>vasanthmss</dc:creator>
      <dc:date>2017-08-29T20:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my search head only sometimes see a peer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297224#M11254</link>
      <description>&lt;P&gt;It wouldn't show up in there, as that only has static search-servers.  This is an index cluster member, which means that the search-servers are added dynamically by the cluster master. The cluster master, in turn, doesn't poll for indexers, but receives indexers as they say they are available.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 21:11:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297224#M11254</guid>
      <dc:creator>duke_splunk_adm</dc:creator>
      <dc:date>2017-08-29T21:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my search head only sometimes see a peer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297225#M11255</link>
      <description>&lt;P&gt;And yes, I did check my distsearch.conf, thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 21:11:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297225#M11255</guid>
      <dc:creator>duke_splunk_adm</dc:creator>
      <dc:date>2017-08-29T21:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my search head only sometimes see a peer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297226#M11256</link>
      <description>&lt;P&gt;One possible scenario to explain your problem : &lt;BR /&gt;
- specifications or configuration is different on that indexer -&amp;gt; he has more work to do OR it is less powerfull than others&lt;BR /&gt;
- at some times, you are creating more search load that the indexer can handle -&amp;gt; load spike on this indexer&lt;BR /&gt;
- this indexer is now slow to respond to sh  -&amp;gt; the search head thinks it's down&lt;/P&gt;

&lt;P&gt;So I would : &lt;BR /&gt;
- investigate why that indexer is different than the others&lt;BR /&gt;
- check search concurrency limit on sh and if needed lower it (lower shedule perc may be enough)&lt;BR /&gt;
- spread your search load over time (schedule window, continous scheduling, skew, ..)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 21:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-does-my-search-head-only-sometimes-see-a-peer/m-p/297226#M11256</guid>
      <dc:creator>maraman_splunk</dc:creator>
      <dc:date>2017-08-29T21:34:19Z</dc:date>
    </item>
  </channel>
</rss>

