Deployment Architecture

How to push configuration bundle from cluster master to indexers- but explicitly DO NOT restart

st4ple
Path Finder

In Indexer Clustering, is there a way to push the configuration bundle from a Cluster Master to the Indexers and explicitly don't restart the Indexers?

I'm thinking there might be an updated configuration bundle (which requires a restart of the Indexers) that I want to distribute to the Indexers but only execute the restart of the Indexers at a later moment (i.e. a scheduled time-window when the load is low on the Indexers).

For Search Head Clustering, this is possible and documented (https://docs.splunk.com/Documentation/Splunk/7.3.1/DistSearch/PropagateSHCconfigurationchanges#Contr...), but for Indexer Clustering I didn't find any mention in the documentation.

0 Karma
1 Solution

dhihoriya_splun
Splunk Employee
Splunk Employee

Hi @st4ple

To push the cluster bundle on the indexer you need a rolling restart on the indexer but it depends on your bundle configuration like some time for some config you just have to reload the indexers no need to restart them (It will automatically done when you are applying cluster bundle to the indexer) but if your configuration needed rolling restart then you can't stage the bundle on all the indexer and schedule a restart activity for any other time.

View solution in original post

dhihoriya_splun
Splunk Employee
Splunk Employee

Hi @st4ple

To push the cluster bundle on the indexer you need a rolling restart on the indexer but it depends on your bundle configuration like some time for some config you just have to reload the indexers no need to restart them (It will automatically done when you are applying cluster bundle to the indexer) but if your configuration needed rolling restart then you can't stage the bundle on all the indexer and schedule a restart activity for any other time.

st4ple
Path Finder

Thanks for your answer, @dhihoriya_splunk . I was hoping that staging bundles for a later restart would be somehow possible for Indexer Clusters since it exists for Search Head Clusters.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...