<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What can be done to alleviate the load on a resource depleted cluster master? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397497#M14407</link>
    <description>&lt;P&gt;Makes perfect sense @SloshBurch - thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Oct 2018 23:29:41 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2018-10-16T23:29:41Z</dc:date>
    <item>
      <title>What can be done to alleviate the load on a resource depleted cluster master?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397491#M14401</link>
      <description>&lt;P&gt;We have a farm that is going to be retired in a couple of months.&lt;/P&gt;

&lt;P&gt;The cluster master hasn't been doing well at all - &lt;A href="https://answers.splunk.com/answers/684524/why-is-the-indexer-cluster-master-being-marked-as.html"&gt;Why is the indexer cluster master being marked as down consistently?&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Support just told us -&lt;/P&gt;

&lt;P&gt;--  The Cluster Master is desperately in need of additional resources, 2 cores and 8 GB of memory is not going to be sufficient. &lt;/P&gt;

&lt;P&gt;Since there is no chance for us to get approval for additional resources on this VM, I wonder what can be done to alleviate the load on this cluster master? &lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 17:42:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397491#M14401</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-10-02T17:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: What can be done to alleviate the load on a resource depleted cluster master?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397492#M14402</link>
      <description>&lt;P&gt;We found out that the indexers had issues to connect to the CM and therefore generated lots of internal data that the system couldn't easily index.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5846i47A5EC98EDC1533D/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;What can we do in such a case? Is there a way to disable _internal indexing in such cases?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 14:43:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397492#M14402</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-10-03T14:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: What can be done to alleviate the load on a resource depleted cluster master?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397493#M14403</link>
      <description>&lt;P&gt;For the sake of completeness from the CM -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$ grep CMPeer &amp;lt; splunkd.log.5.instability | wc -l
71999 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It covers this time frame -&lt;BR /&gt;
10-03-2018 01:11:11.213 -0500&lt;BR /&gt;
10-03-2018 01:11:59.532 -0500&lt;/P&gt;

&lt;P&gt;The messages look like -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;10-03-2018 01:11:59.532 -0500 INFO  CMPeer - peer=12E6ED7C-9765-46F1-8883-5F34834E82F4 peer_name=&amp;lt;indexer&amp;gt; bid=&amp;lt;index name&amp;gt;~4485~3CA07398-A043-4E1E-BA20-233C66372471 transitioning from=Searchable to=SearchablePendingMask oldmask=0x4 newmask=0x5 reason="swap primaries"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 03 Oct 2018 16:42:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397493#M14403</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-10-03T16:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: What can be done to alleviate the load on a resource depleted cluster master?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397494#M14404</link>
      <description>&lt;P&gt;2 core and 8gb is &lt;EM&gt;not&lt;/EM&gt; going to cut it... but there are some configs we can &lt;EM&gt;try&lt;/EM&gt; to tinker with (no promises):&lt;/P&gt;

&lt;P&gt;indexers server.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;heartbeat_period: 1-&amp;gt;10
cxn_timeout = 60-&amp;gt;300
send_timeout = 60-&amp;gt;300
rcv_timeout = 60-&amp;gt; 300
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;CM server.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;heartbeat_timeout = 60-&amp;gt;300
max_fixup_time_ms = 5000​
cxn_timeout = 60-&amp;gt;300
send_timeout = 60-&amp;gt;300
rcv_timeout = 60-&amp;gt; 300
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 09 Oct 2018 06:46:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397494#M14404</guid>
      <dc:creator>dxu_splunk</dc:creator>
      <dc:date>2018-10-09T06:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: What can be done to alleviate the load on a resource depleted cluster master?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397495#M14405</link>
      <description>&lt;P&gt;My understanding of the issue is that the Cluster Master is having trouble coordinating your Search and Replication factors among the peers. So, even if you disable indexing _internal (which I promise you WILL regret doing that) you will eventually see this happen as bucket load increases with data volume.&lt;/P&gt;

&lt;P&gt;Is your search factor and replication factor wildly high? Did you mess with the size of buckets? Both of those tuning could be causing your more issues.&lt;/P&gt;

&lt;P&gt;At the end of the day, the software was designed for minimum specifications that are not being provided. If it helps sell your need for more power: a car can't really drive well on one wheel if it requires four.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 13:25:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397495#M14405</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2018-10-10T13:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: What can be done to alleviate the load on a resource depleted cluster master?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397496#M14406</link>
      <description>&lt;P&gt;Much appreciated @dxu_splunk !!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 23:28:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397496#M14406</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-10-16T23:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: What can be done to alleviate the load on a resource depleted cluster master?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397497#M14407</link>
      <description>&lt;P&gt;Makes perfect sense @SloshBurch - thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 23:29:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-can-be-done-to-alleviate-the-load-on-a-resource-depleted/m-p/397497#M14407</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-10-16T23:29:41Z</dc:date>
    </item>
  </channel>
</rss>

