<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: reboot splunk instance after OS patching in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/reboot-splunk-instance-after-OS-patching/m-p/402657#M4610</link>
    <description>&lt;P&gt;I would suggest you perform the proposed activity on a test server [ can be single instance, if you don't have a cluster setup] which same OS level patches/versions and same version of splunk instance as prod. This can prove that the reboot of the OS works fine and the splunk starts up clean.&lt;BR /&gt;
- Ensure your instances are setup boot enable splunk &lt;BR /&gt;
- watch for any errors in splunkd.logs and python logs related to OS and splunk apps/add-ons on your instance&lt;BR /&gt;
- If you are happy, you can select a quite period [ out of office hours, when the load and incoming data is minimal], put the master in maintenance mode, restart/reboot the cluster master and ensure it comes up and all peer nodes connect successfully.&lt;BR /&gt;
- take out each search peer on to a maintenance mode or offline  (ensure they are are in maintenance mode) and reboot and re-enable them&lt;BR /&gt;
- between each peer node reboot, ensure the nodes &lt;/P&gt;

&lt;P&gt;You may also want to refer to &lt;A href="https://answers.splunk.com/answers/352976/what-is-the-correct-procedure-to-patch-the-os-and.html"&gt;https://answers.splunk.com/answers/352976/what-is-the-correct-procedure-to-patch-the-os-and.html&lt;/A&gt; &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.0/Indexer/Upgradeacluster#Upgrade_to_a_maintenance_release"&gt;https://docs.splunk.com/Documentation/Splunk/7.1.0/Indexer/Upgradeacluster#Upgrade_to_a_maintenance_release&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Apr 2019 07:52:03 GMT</pubDate>
    <dc:creator>lakshman239</dc:creator>
    <dc:date>2019-04-09T07:52:03Z</dc:date>
    <item>
      <title>reboot splunk instance after OS patching</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/reboot-splunk-instance-after-OS-patching/m-p/402656#M4609</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.2/Indexer/Userollingrestart"&gt;link text&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;We patch our OS last week and OS admin advise us to reboto the Indexers once. we have multistie scenerios. (6+6).&lt;/P&gt;

&lt;P&gt;Please suggest a best method to reboot OS without effecting index searching capability.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 07:10:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/reboot-splunk-instance-after-OS-patching/m-p/402656#M4609</guid>
      <dc:creator>rashid47010</dc:creator>
      <dc:date>2019-04-09T07:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: reboot splunk instance after OS patching</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/reboot-splunk-instance-after-OS-patching/m-p/402657#M4610</link>
      <description>&lt;P&gt;I would suggest you perform the proposed activity on a test server [ can be single instance, if you don't have a cluster setup] which same OS level patches/versions and same version of splunk instance as prod. This can prove that the reboot of the OS works fine and the splunk starts up clean.&lt;BR /&gt;
- Ensure your instances are setup boot enable splunk &lt;BR /&gt;
- watch for any errors in splunkd.logs and python logs related to OS and splunk apps/add-ons on your instance&lt;BR /&gt;
- If you are happy, you can select a quite period [ out of office hours, when the load and incoming data is minimal], put the master in maintenance mode, restart/reboot the cluster master and ensure it comes up and all peer nodes connect successfully.&lt;BR /&gt;
- take out each search peer on to a maintenance mode or offline  (ensure they are are in maintenance mode) and reboot and re-enable them&lt;BR /&gt;
- between each peer node reboot, ensure the nodes &lt;/P&gt;

&lt;P&gt;You may also want to refer to &lt;A href="https://answers.splunk.com/answers/352976/what-is-the-correct-procedure-to-patch-the-os-and.html"&gt;https://answers.splunk.com/answers/352976/what-is-the-correct-procedure-to-patch-the-os-and.html&lt;/A&gt; &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.0/Indexer/Upgradeacluster#Upgrade_to_a_maintenance_release"&gt;https://docs.splunk.com/Documentation/Splunk/7.1.0/Indexer/Upgradeacluster#Upgrade_to_a_maintenance_release&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 07:52:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/reboot-splunk-instance-after-OS-patching/m-p/402657#M4610</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-04-09T07:52:03Z</dc:date>
    </item>
  </channel>
</rss>

