<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic KV store on the newly built SH server not joining the KV cluster but part of SH cluster. in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/KV-store-on-the-newly-built-SH-server-not-joining-the-KV-cluster/m-p/705956#M28881</link>
    <description>&lt;P&gt;We have new SH node which we are trying to add to the Search head cluster,&amp;nbsp; updated the configs in shcluster config and other configs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;After adding this node in the cluster , now we have two nodes as pert of&amp;nbsp; the SH cluster.&lt;/P&gt;&lt;P&gt;We can see both the nodes up and running part of the cluster,&amp;nbsp; &amp;nbsp;when we check it with "splunk show shcluster-status".&lt;/P&gt;&lt;P&gt;But, when we check the kvstore status with " splunk show kvstore-status" old nodes shows as captain , but the newly built node is not joining this cluster and giving the below error in the logs.&lt;/P&gt;&lt;P&gt;Error in Splunkd log on the search head which has issue..&lt;/P&gt;&lt;P&gt;12-04-2024 16:36:45.402 +0000 ERROR KVStoreBulletinBoardManager [534432 KVStoreConfigurationThread] - Local KV Store has replication issues. See introspection data and mongod.log for details. Cluster has not been configured on this member. KVStore cluster has not been configured&lt;BR /&gt;&lt;BR /&gt;We have configured all the cluster related info on the newly built search head server(server.conf), dont see any configs missing.&lt;BR /&gt;&lt;BR /&gt;We also see below error on the SH ui page messages tab..&lt;/P&gt;&lt;P&gt;Failed to synchronize configuration with KVStore cluster. Quorum check failed because not enough voting nodes responded; required 2 but only the following 1 voting nodes responded: search-head01:8191; the following nodes did not respond affirmatively: search-head01:8191 failed with Error connecting to search-head01:8191 (172.**.***.**:8191) :: caused by :: compression disabled.&lt;BR /&gt;&lt;BR /&gt;Anyone else faced this error before...need some support here...&lt;/P&gt;</description>
    <pubDate>Wed, 04 Dec 2024 19:57:23 GMT</pubDate>
    <dc:creator>HarishSamudrala</dc:creator>
    <dc:date>2024-12-04T19:57:23Z</dc:date>
    <item>
      <title>KV store on the newly built SH server not joining the KV cluster but part of SH cluster.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/KV-store-on-the-newly-built-SH-server-not-joining-the-KV-cluster/m-p/705956#M28881</link>
      <description>&lt;P&gt;We have new SH node which we are trying to add to the Search head cluster,&amp;nbsp; updated the configs in shcluster config and other configs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;After adding this node in the cluster , now we have two nodes as pert of&amp;nbsp; the SH cluster.&lt;/P&gt;&lt;P&gt;We can see both the nodes up and running part of the cluster,&amp;nbsp; &amp;nbsp;when we check it with "splunk show shcluster-status".&lt;/P&gt;&lt;P&gt;But, when we check the kvstore status with " splunk show kvstore-status" old nodes shows as captain , but the newly built node is not joining this cluster and giving the below error in the logs.&lt;/P&gt;&lt;P&gt;Error in Splunkd log on the search head which has issue..&lt;/P&gt;&lt;P&gt;12-04-2024 16:36:45.402 +0000 ERROR KVStoreBulletinBoardManager [534432 KVStoreConfigurationThread] - Local KV Store has replication issues. See introspection data and mongod.log for details. Cluster has not been configured on this member. KVStore cluster has not been configured&lt;BR /&gt;&lt;BR /&gt;We have configured all the cluster related info on the newly built search head server(server.conf), dont see any configs missing.&lt;BR /&gt;&lt;BR /&gt;We also see below error on the SH ui page messages tab..&lt;/P&gt;&lt;P&gt;Failed to synchronize configuration with KVStore cluster. Quorum check failed because not enough voting nodes responded; required 2 but only the following 1 voting nodes responded: search-head01:8191; the following nodes did not respond affirmatively: search-head01:8191 failed with Error connecting to search-head01:8191 (172.**.***.**:8191) :: caused by :: compression disabled.&lt;BR /&gt;&lt;BR /&gt;Anyone else faced this error before...need some support here...&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 19:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/KV-store-on-the-newly-built-SH-server-not-joining-the-KV-cluster/m-p/705956#M28881</guid>
      <dc:creator>HarishSamudrala</dc:creator>
      <dc:date>2024-12-04T19:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: KV store on the newly built SH server not joining the KV cluster but part of SH cluster.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/KV-store-on-the-newly-built-SH-server-not-joining-the-KV-cluster/m-p/706047#M28891</link>
      <description>&lt;P&gt;A cluster requires 3 or more (odd counts only).&amp;nbsp; Quorum is obtained by having 50%+1 in sync.&amp;nbsp; Having only 2 nodes means there will never be quorum.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 18:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/KV-store-on-the-newly-built-SH-server-not-joining-the-KV-cluster/m-p/706047#M28891</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-12-05T18:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: KV store on the newly built SH server not joining the KV cluster but part of SH cluster.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/KV-store-on-the-newly-built-SH-server-not-joining-the-KV-cluster/m-p/706054#M28892</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194981"&gt;@dural_yyz&lt;/a&gt;Close but not quite.&lt;/P&gt;&lt;P&gt;SHC uses raft algorithm. It will work with just two nodes but won't handle an outage of any node.&lt;/P&gt;&lt;P&gt;True, it needs quorum to elect a leader but a quorum can be obtained in a 2-node cluster by having votes of both nodes. The problem starts when one node is down because with just one alive node you can never get a quorum.&lt;/P&gt;&lt;P&gt;The same is also true for any even number of nodes - it needs (N/2)+1 votes for quorum so while an even-node cluster can survive (N/2)-1 nodes outage, it cannot function if you have an even split like half of the nodes in one datacenter, another half in another and a network outage. So odd-noded clusters are simply more cost-effective because adding one more node to make a cluster even-noded doesn't increase resilience.&lt;/P&gt;&lt;P&gt;Additionally, with Splunk's SHC you can simply enforce a manually set captain, bypassing the normal raft election.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/265442"&gt;@HarishSamudrala&lt;/a&gt;Actually SHC consists of two "separate" clusters - one is your normal cluster formed of splunkd processes, another one is a "hidden" cluster formed of mongodb (kvstore) instances. Typically they share captaincy but it's not a must. In your case it seems that due to some communication problems the kvstore cluster can't get the nodes to communicate with each other so you can't get them both to form a quorum and decide which one is a captain.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 20:00:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/KV-store-on-the-newly-built-SH-server-not-joining-the-KV-cluster/m-p/706054#M28892</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-05T20:00:20Z</dc:date>
    </item>
  </channel>
</rss>

