<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Totally Disable Search head Clustering in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393919#M114497</link>
    <description>&lt;P&gt;I have tried that command but I am getting issues, when I run disable member command on the captain, the command is getting stuck and doing nothing ? In my case I have 2 nodes in a cluster the member node was removed successfully.&lt;/P&gt;

&lt;P&gt;But running that command on captain is not working, as I think it is trying to find the another captain to remove that member. What can be done in this case ?&lt;/P&gt;

&lt;P&gt;Should I comment "clustering" stanza on Captain and take a restart ? Please advise ?&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jul 2019 05:25:32 GMT</pubDate>
    <dc:creator>pgadhari</dc:creator>
    <dc:date>2019-07-24T05:25:32Z</dc:date>
    <item>
      <title>Totally Disable Search head Clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393911#M114489</link>
      <description>&lt;P&gt;I have 2 nodes in my Search Head cluster and want to disable the Search head Clustering fully. I have a deployer also, which I used during configuration of Search Head Cluster. &lt;/P&gt;

&lt;P&gt;In the documentations, I can see only "Remove cluster member" but there is no documentation on how to disable and remove Search Head Clustering fully. Please help on how to disable and remove Search head cluster ?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 05:29:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393911#M114489</guid>
      <dc:creator>pgadhari</dc:creator>
      <dc:date>2019-07-22T05:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: Totally Disable Search head Clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393912#M114490</link>
      <description>&lt;P&gt;Splunk recommends at least 3 instances to create search head cluster. Run below commands in each search-head members to disable search-head clustering.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Remove the member:&lt;BR /&gt;
&lt;CODE&gt;splunk remove shcluster-member&lt;/CODE&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Disable the member:&lt;BR /&gt;
&lt;CODE&gt;splunk disable shcluster-config&lt;/CODE&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Clean the KVStore:&lt;BR /&gt;
&lt;CODE&gt;splunk clean kvstore --cluster&lt;/CODE&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;&lt;STRONG&gt;Reference:&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.1/DistSearch/Removeaclustermember"&gt;https://docs.splunk.com/Documentation/Splunk/6.5.1/DistSearch/Removeaclustermember&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 05:48:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393912#M114490</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-07-22T05:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Totally Disable Search head Clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393913#M114491</link>
      <description>&lt;P&gt;But I think this will only disable one of the member of the cluster. Whether it will totally disable Search head clustering ? Also, whether I have to do any steps on Deployer to disable any services on it ? Please advise ?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 06:06:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393913#M114491</guid>
      <dc:creator>pgadhari</dc:creator>
      <dc:date>2019-07-22T06:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Totally Disable Search head Clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393914#M114492</link>
      <description>&lt;P&gt;I have updated my answer with steps. Kindly accept the answer if it's helpful.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 06:17:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393914#M114492</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-07-22T06:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Totally Disable Search head Clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393915#M114493</link>
      <description>&lt;P&gt;sure I will try this out and revert back. Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 12:09:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393915#M114493</guid>
      <dc:creator>pgadhari</dc:creator>
      <dc:date>2019-07-22T12:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: Totally Disable Search head Clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393916#M114494</link>
      <description>&lt;P&gt;I have 2 nodes in my search head cluster, do I need to do above steps on both the nodes one by one ? &lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 07:28:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393916#M114494</guid>
      <dc:creator>pgadhari</dc:creator>
      <dc:date>2019-07-23T07:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Totally Disable Search head Clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393917#M114495</link>
      <description>&lt;P&gt;Yes. Execute these commands on each search-head members (one by one).&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 07:43:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393917#M114495</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-07-23T07:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Totally Disable Search head Clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393918#M114496</link>
      <description>&lt;P&gt;ok got it. Thanks. I will revert back.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 07:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393918#M114496</guid>
      <dc:creator>pgadhari</dc:creator>
      <dc:date>2019-07-23T07:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Totally Disable Search head Clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393919#M114497</link>
      <description>&lt;P&gt;I have tried that command but I am getting issues, when I run disable member command on the captain, the command is getting stuck and doing nothing ? In my case I have 2 nodes in a cluster the member node was removed successfully.&lt;/P&gt;

&lt;P&gt;But running that command on captain is not working, as I think it is trying to find the another captain to remove that member. What can be done in this case ?&lt;/P&gt;

&lt;P&gt;Should I comment "clustering" stanza on Captain and take a restart ? Please advise ?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 05:25:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393919#M114497</guid>
      <dc:creator>pgadhari</dc:creator>
      <dc:date>2019-07-24T05:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: Totally Disable Search head Clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393920#M114498</link>
      <description>&lt;P&gt;Update 'disabled' key to &lt;STRONG&gt;1&lt;/STRONG&gt; in 'shclustering' stanza of your 'server.conf' file and restart the Splunk instance.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[shclustering]
disabled = 1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 24 Jul 2019 06:34:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393920#M114498</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-07-24T06:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: Totally Disable Search head Clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393921#M114499</link>
      <description>&lt;P&gt;You would have a configuration in your servers.conf. &lt;BR /&gt;
Ideally, this should be in your system/local. But can differ depending on your configuration.&lt;/P&gt;

&lt;P&gt;The servers.conf will have a stanza [shclustering].&lt;BR /&gt;&lt;BR /&gt;
Remove all configuration under this stanza on all your SH. &lt;BR /&gt;
Do a restart.&lt;BR /&gt;
Your SH clustering will be removed.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 07:00:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Totally-Disable-Search-head-Clustering/m-p/393921#M114499</guid>
      <dc:creator>chinmoya</dc:creator>
      <dc:date>2019-07-24T07:00:55Z</dc:date>
    </item>
  </channel>
</rss>

