<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why Search Head in a Search Head Cluster is in manual detention, but still taking searches? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/593485#M25530</link>
    <description>&lt;P&gt;I need to upgrade a Search Head Cluster from 7.3.4 to 8.1.9 and I have run the first two commands:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;splunk upgrade-init shcluster-members&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;splunk edit shcluster-config -manual_detention on&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We are monitoring the active searches using the following command:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;splunk list shcluster-member-info | grep "active"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And we see:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;active_historical_search_count:1&lt;BR /&gt;active_realtime_search_count:0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And it seemed to never reduce down to 0 for the active_historical_search_count, but after 90 minutes, it seems to have come down to 0. We checked the currently-running searches and found some new searches running on the detention server after 1 hour.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;We have the following set in the server.conf:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;decommission_force_finish_idle_time = 0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;decommission_node_force_timeout = 300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;decommission_search_jobs_wait_secs = 180&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;...so why is it taking 90 minutes to stop running savedsearches?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;We did find some savedsearches that were running for long times and we fixed them, but should not all new searches be moved to another server once it is in manual detention? What can I do to fix this, so that my SHC can be upgraded?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Sep 2023 17:26:03 GMT</pubDate>
    <dc:creator>BlueSocket</dc:creator>
    <dc:date>2023-09-20T17:26:03Z</dc:date>
    <item>
      <title>Why Search Head in a Search Head Cluster is in manual detention, but still taking searches?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/593485#M25530</link>
      <description>&lt;P&gt;I need to upgrade a Search Head Cluster from 7.3.4 to 8.1.9 and I have run the first two commands:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;splunk upgrade-init shcluster-members&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;splunk edit shcluster-config -manual_detention on&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We are monitoring the active searches using the following command:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;splunk list shcluster-member-info | grep "active"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And we see:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;active_historical_search_count:1&lt;BR /&gt;active_realtime_search_count:0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And it seemed to never reduce down to 0 for the active_historical_search_count, but after 90 minutes, it seems to have come down to 0. We checked the currently-running searches and found some new searches running on the detention server after 1 hour.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;We have the following set in the server.conf:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;decommission_force_finish_idle_time = 0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;decommission_node_force_timeout = 300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;decommission_search_jobs_wait_secs = 180&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;...so why is it taking 90 minutes to stop running savedsearches?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;We did find some savedsearches that were running for long times and we fixed them, but should not all new searches be moved to another server once it is in manual detention? What can I do to fix this, so that my SHC can be upgraded?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 17:26:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/593485#M25530</guid>
      <dc:creator>BlueSocket</dc:creator>
      <dc:date>2023-09-20T17:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head in a Search Head Cluster is in manual detention, but still taking searches</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/594756#M25564</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;based on documentation those&amp;nbsp;&lt;SPAN&gt;decommission_* parameters are valid only on search peers (indexers) or cluster master and only when you are doing "splunk offline" command. See:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/DistSearch/SHdetention#How_existing_searches_are_handled" target="_blank" rel="noopener"&gt;How existing searches are handled&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/Admin/Serverconf" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/Admin/Serverconf&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;When you have put SHC&amp;nbsp;member manually into detention mode, it just&amp;nbsp;wait that&amp;nbsp;searches&amp;nbsp;will&amp;nbsp;finished.&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;On a search head that is in manual detention but not a part of a searchable rolling restart&lt;/STRONG&gt;. These searches will run to completion.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;On a search head that is a part of a rolling upgrade&lt;/STRONG&gt;. During rolling upgrade of a search head cluster, you can put a single search head into manual detention and wait for the existing search jobs to run to completion before you shut down the search head.&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;I'm not sure if there is any way to&amp;nbsp;force&amp;nbsp;&lt;/SPAN&gt;gracefully those sessions on SHC member? I usually just wait some time and after that cancel those jobs if needed.&lt;/P&gt;&lt;P&gt;I agree with you that on detention mode it shouldn't accept any new queries from schedule or users anymore. But maybe there is error in documentation and it means that it don't accept any new sessions from user to this node?&amp;nbsp;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 21:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/594756#M25564</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-04-21T21:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head in a Search Head Cluster is in manual detention, but still taking searches</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/646320#M27198</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;I have the same issue. The "active_historical_search_count" does not go to 0.&lt;/P&gt;&lt;P&gt;I don't see any running searches under "jobs" in gui.&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;I usually just wait some time and after that cancel those jobs if needed"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;How do you find and cancel the jobs?&lt;/P&gt;&lt;P&gt;Regards Alex&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 12:39:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/646320#M27198</guid>
      <dc:creator>alexanderl</dc:creator>
      <dc:date>2023-06-08T12:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head in a Search Head Cluster is in manual detention, but still taking searches</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/646376#M27201</link>
      <description>The easiest way is shutdown node and start update. Another option is check what are running jobs and then cancel those one by on from GUI.</description>
      <pubDate>Thu, 08 Jun 2023 21:00:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/646376#M27201</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-08T21:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head in a Search Head Cluster is in manual detention, but still taking searches + 1</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/658102#M27460</link>
      <description>&lt;P&gt;And another not so happy user here.&lt;/P&gt;&lt;P&gt;The documentation clearly states "&lt;EM&gt;When a search head cluster member is in manual detention, it stops accepting all new searches from the search scheduler or from users. Existing ad-hoc and scheduled search jobs run to completion. New scheduled searches are distributed by the captain to search head cluster members that are up and not in detention.&lt;/EM&gt;"&lt;/P&gt;&lt;P&gt;As expected, an interactive search is refused.&lt;/P&gt;&lt;P&gt;Yet when I monitor the &lt;EM&gt;active_historical_search_count&lt;/EM&gt; of a member in detention, I observe the count going up and down.&lt;/P&gt;&lt;P&gt;When I look at the Job Manager screen, I see lots of newly created jobs.&lt;/P&gt;&lt;P&gt;Either I misunderstood the detention feature, or the documentation is off the mark, or there is a bug.&lt;/P&gt;&lt;P&gt;What is it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 10:02:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/658102#M27460</guid>
      <dc:creator>vgrote</dc:creator>
      <dc:date>2023-09-20T10:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head in a Search Head Cluster is in manual detention, but still taking searches + 1</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/658348#M27467</link>
      <description>You should ask clarification from doc team. Just leave a comment o that document page and the will be back to you later.</description>
      <pubDate>Thu, 21 Sep 2023 20:57:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-Search-Head-in-a-Search-Head-Cluster-is-in-manual-detention/m-p/658348#M27467</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-09-21T20:57:08Z</dc:date>
    </item>
  </channel>
</rss>

