Deployment Architecture

For a search head cluster to operate, how many of its members need to be running?

Steve_G_
Splunk Employee
Splunk Employee

For a search head cluster to operate, how many of its members need to be running?

1 Solution

Steve_G_
Splunk Employee
Splunk Employee

The proper functioning of a search head cluster requires that a majority of all its members be up and running.

This is a consequence of the captain election process. To elect a captain, a majority of all cluster members must agree on a captain. It is important to emphasize that the election requires a majority of all members, not just of the currently running members. If only 50% or less of the members are running, therefore, the cluster cannot elect a captain.

For example, a cluster of seven members needs at least four of those members to be running. Similarly, a cluster of six members also requires that a minimum of four members be running. If only three members, of a six or seven member cluster, are running, they do not constitute a majority and thus cannot elect a captain.

Without a captain, the cluster cannot function properly. The individual search heads will continue to service ad hoc search requests, but they will not coordinate their efforts and they will not run scheduled searches.

For more information on the captain election process and its requirements, see http://docs.splunk.com/Documentation/Splunk/6.2.2/DistSearch/SHCarchitecture#Captain_election

View solution in original post

Steve_G_
Splunk Employee
Splunk Employee

The proper functioning of a search head cluster requires that a majority of all its members be up and running.

This is a consequence of the captain election process. To elect a captain, a majority of all cluster members must agree on a captain. It is important to emphasize that the election requires a majority of all members, not just of the currently running members. If only 50% or less of the members are running, therefore, the cluster cannot elect a captain.

For example, a cluster of seven members needs at least four of those members to be running. Similarly, a cluster of six members also requires that a minimum of four members be running. If only three members, of a six or seven member cluster, are running, they do not constitute a majority and thus cannot elect a captain.

Without a captain, the cluster cannot function properly. The individual search heads will continue to service ad hoc search requests, but they will not coordinate their efforts and they will not run scheduled searches.

For more information on the captain election process and its requirements, see http://docs.splunk.com/Documentation/Splunk/6.2.2/DistSearch/SHCarchitecture#Captain_election

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...