We have an indexer which is going to be down for several days, so in preparation for that I performed these steps:
splunk offlineon site1 indexer
Changed server.conf on the cluster master node from this
Bounced cluster master
I thought that would prevent search & replication messages from cluttering splunkd.log while site1 was unavailable, but I am getting this combination of warnings about 1500 times an hour:
WARN CMMessages - got genid thats invalid or out of range, setting to INVALID_GENID, jn=18446744073709551616.000000 WARN CMSlave - handleHeartbeatDone: successful heartbeat. Forcing a re-add, Reason="Proxy is in disconnect state."
The system also seems to think that the indexes are not fully searchable, but I think that there is a primary bucket for everything the remaining site2.
Should I do anything about these warnings?
I would open a support case.
I just realized that I never updated this with what I figured out.
On the cluster master (
etc\system\local\server.conf) I had to change this:
available_sites = site1, site2
available_sites = site2