<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What happened to my Splunk AWS Instance? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426126#M74694</link>
    <description>&lt;P&gt;I'm currently ingesting a data from db connect. While ingesting I tried to do a search in a search head led by ELB but then an error came out. It seems it encountered a problem with one of my peers. I accidentally refreshed so I didn't manage to capture the error message.&lt;/P&gt;

&lt;P&gt;I checked my Cluster Master and indeed, one of the peers is down. I can ping the instance but I can't access it by ssh. We already encountered this situation just the other day and AWS sent us the Cloudwatch Log of the instance. It reported that it caused a memory spike..&lt;/P&gt;

&lt;P&gt;Are there any recommendations on what to do?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Raj&lt;/P&gt;</description>
    <pubDate>Fri, 08 Mar 2019 05:41:03 GMT</pubDate>
    <dc:creator>rajyah</dc:creator>
    <dc:date>2019-03-08T05:41:03Z</dc:date>
    <item>
      <title>What happened to my Splunk AWS Instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426126#M74694</link>
      <description>&lt;P&gt;I'm currently ingesting a data from db connect. While ingesting I tried to do a search in a search head led by ELB but then an error came out. It seems it encountered a problem with one of my peers. I accidentally refreshed so I didn't manage to capture the error message.&lt;/P&gt;

&lt;P&gt;I checked my Cluster Master and indeed, one of the peers is down. I can ping the instance but I can't access it by ssh. We already encountered this situation just the other day and AWS sent us the Cloudwatch Log of the instance. It reported that it caused a memory spike..&lt;/P&gt;

&lt;P&gt;Are there any recommendations on what to do?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Raj&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 05:41:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426126#M74694</guid>
      <dc:creator>rajyah</dc:creator>
      <dc:date>2019-03-08T05:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: What happened to my Splunk AWS Instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426127#M74695</link>
      <description>&lt;P&gt;And now the the other indexer is down too..&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 05:41:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426127#M74695</guid>
      <dc:creator>rajyah</dc:creator>
      <dc:date>2019-03-08T05:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: What happened to my Splunk AWS Instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426128#M74696</link>
      <description>&lt;P&gt;To be honest, this does not sound like a Splunk question. You should probably head over to the AWS forums and ask your question there, and consider opening a case with AWS support.&lt;/P&gt;

&lt;P&gt;However, I must admit I am a bit confused by your description. &lt;BR /&gt;
You mention you are using an ELB - I presume because you are running a Search Head Cluster? &lt;BR /&gt;
So I have to ask if this is an Indexer Peer which is failing, or a SHC member?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 10:59:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426128#M74696</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-08T10:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: What happened to my Splunk AWS Instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426129#M74697</link>
      <description>&lt;P&gt;Hmm.. true.&lt;/P&gt;

&lt;P&gt;I'm running a clustered environment sir Nick and it is one of the indexer peers failing. It started working again after restarting the instance but I'm worrying that it might happen again.&lt;/P&gt;

&lt;P&gt;Thanks for the response!&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 14:09:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426129#M74697</guid>
      <dc:creator>rajyah</dc:creator>
      <dc:date>2019-03-08T14:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: What happened to my Splunk AWS Instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426130#M74698</link>
      <description>&lt;P&gt;I would start by looking at the logs you can get from the AWS console - When a machine 'crashes' often this log can give you an insight into anything it spat out on the console just before it died.&lt;BR /&gt;
I'd suggest getting AWS to help you look into it if it happens again - Since your indexers are clustered hopefully you have enough replicated copies to keep your data searchable while they look into it.&lt;/P&gt;

&lt;P&gt;Of course, you could be overwhelming the instance - you could consider increasing the instance size?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 14:22:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426130#M74698</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-08T14:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: What happened to my Splunk AWS Instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426131#M74699</link>
      <description>&lt;P&gt;@rajyah Stop and start your instance from AWS console .&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 16:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426131#M74699</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2019-03-08T16:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: What happened to my Splunk AWS Instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426132#M74700</link>
      <description>&lt;P&gt;Yes, we think that we're overloading the instance and thinking of increasing its size.&lt;/P&gt;

&lt;P&gt;Thanks for the response sir Nick!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 04:03:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-happened-to-my-Splunk-AWS-Instance/m-p/426132#M74700</guid>
      <dc:creator>rajyah</dc:creator>
      <dc:date>2019-03-13T04:03:44Z</dc:date>
    </item>
  </channel>
</rss>

