Deployment Architecture

How to push configuration bundle from cluster master to indexers- but explicitly DO NOT restart

st4ple
Path Finder

In Indexer Clustering, is there a way to push the configuration bundle from a Cluster Master to the Indexers and explicitly don't restart the Indexers?

I'm thinking there might be an updated configuration bundle (which requires a restart of the Indexers) that I want to distribute to the Indexers but only execute the restart of the Indexers at a later moment (i.e. a scheduled time-window when the load is low on the Indexers).

For Search Head Clustering, this is possible and documented (https://docs.splunk.com/Documentation/Splunk/7.3.1/DistSearch/PropagateSHCconfigurationchanges#Contr...), but for Indexer Clustering I didn't find any mention in the documentation.

0 Karma
1 Solution

dhihoriya_splun
Splunk Employee
Splunk Employee

Hi @st4ple

To push the cluster bundle on the indexer you need a rolling restart on the indexer but it depends on your bundle configuration like some time for some config you just have to reload the indexers no need to restart them (It will automatically done when you are applying cluster bundle to the indexer) but if your configuration needed rolling restart then you can't stage the bundle on all the indexer and schedule a restart activity for any other time.

View solution in original post

dhihoriya_splun
Splunk Employee
Splunk Employee

Hi @st4ple

To push the cluster bundle on the indexer you need a rolling restart on the indexer but it depends on your bundle configuration like some time for some config you just have to reload the indexers no need to restart them (It will automatically done when you are applying cluster bundle to the indexer) but if your configuration needed rolling restart then you can't stage the bundle on all the indexer and schedule a restart activity for any other time.

st4ple
Path Finder

Thanks for your answer, @dhihoriya_splunk . I was hoping that staging bundles for a later restart would be somehow possible for Indexer Clusters since it exists for Search Head Clusters.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...