Deployment Architecture

Can we disable rolling restart for Search Head Clustering?

philip_wong
Communicator

We have an internal built application management tool to start Splunk and monitor it's process status.
Search Head Clustering rolling restarting would basically break that.
Provided that we'd like to manage the restart ourselves, can we turn this feature off?

I saw an attribute called "percent_peers_to_restart" in server.conf. Can we achieve that by setting it to 0?

sduff_splunk
Splunk Employee
Splunk Employee

I would be hesitant at trying to replace the deployer functionality. The Search Heads are meant to be kept in close synchronization, so that field extractions, lookups, etc... are kept the same and the same results are returned regardless of search head.

0 Karma

dflodstrom
Builder

The deployer doesn't replicate search results, field extractions, lookups, etc.

0 Karma

Steve_G_
Splunk Employee
Splunk Employee

It's unclear from your question what the exact circumstances are for which you are trying to avoid a rolling restart. In search head clustering, rolling restart occurs only in two situations:

You say that you are using an "internal built application management tool". If that tool replaces the deployer functionality, then you can just restart members as you want, using whatever method you prefer.

If that tool does not replace the deployer, then presumably your question is about how to avoid a potential rolling restart after pushing updates via the deployer. Unfortunately, there is no way to prevent a potential rolling restart, post-deployer push. Your plan to set percent_peers_to_restart to 0 won't do that, because, as the spec file for server.conf states, "regardless of setting, a minimum of 1 peer will be restarted per round."

philip_wong
Communicator

Our intention is not the replace deployer or configuration distribution mechanism. We just need stop/start to be managed by ourselves. I think it would be fair if Splunk can break rolling restart as optional.

Steve_G_
Splunk Employee
Splunk Employee

Thank you for the suggestion. We will make sure this gets added as a product enhancement request.

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...