Deployment Architecture

For a search head cluster to operate, how many of its members need to be running?

Steve_G_
Splunk Employee
Splunk Employee

For a search head cluster to operate, how many of its members need to be running?

1 Solution

Steve_G_
Splunk Employee
Splunk Employee

The proper functioning of a search head cluster requires that a majority of all its members be up and running.

This is a consequence of the captain election process. To elect a captain, a majority of all cluster members must agree on a captain. It is important to emphasize that the election requires a majority of all members, not just of the currently running members. If only 50% or less of the members are running, therefore, the cluster cannot elect a captain.

For example, a cluster of seven members needs at least four of those members to be running. Similarly, a cluster of six members also requires that a minimum of four members be running. If only three members, of a six or seven member cluster, are running, they do not constitute a majority and thus cannot elect a captain.

Without a captain, the cluster cannot function properly. The individual search heads will continue to service ad hoc search requests, but they will not coordinate their efforts and they will not run scheduled searches.

For more information on the captain election process and its requirements, see http://docs.splunk.com/Documentation/Splunk/6.2.2/DistSearch/SHCarchitecture#Captain_election

View solution in original post

Steve_G_
Splunk Employee
Splunk Employee

The proper functioning of a search head cluster requires that a majority of all its members be up and running.

This is a consequence of the captain election process. To elect a captain, a majority of all cluster members must agree on a captain. It is important to emphasize that the election requires a majority of all members, not just of the currently running members. If only 50% or less of the members are running, therefore, the cluster cannot elect a captain.

For example, a cluster of seven members needs at least four of those members to be running. Similarly, a cluster of six members also requires that a minimum of four members be running. If only three members, of a six or seven member cluster, are running, they do not constitute a majority and thus cannot elect a captain.

Without a captain, the cluster cannot function properly. The individual search heads will continue to service ad hoc search requests, but they will not coordinate their efforts and they will not run scheduled searches.

For more information on the captain election process and its requirements, see http://docs.splunk.com/Documentation/Splunk/6.2.2/DistSearch/SHCarchitecture#Captain_election

Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...