Deployment Architecture

How to remove a search head member from cluster ?

danielwan
Explorer

I am following the below process to remove a search head cluster member
https://docs.splunk.com/Documentation/Splunk/7.0.1/DistSearch/Removeaclustermember

I run the following CLI on the host I would like to remove from search head cluster and got following error.

sudo /opt/splunk/bin/splunk remove shcluster-member -auth admin:yahoo7
https://"captain host mgmt uri" ERROR: Raft not initialized. This means that dynamic captain mode was not set in server.conf

I am using static Splunk search head captain than the dynamic election. What is the correct approach to remove search head member when I using static captain?

0 Karma

p_gurav
Champion

Hi,
Can you make captain dynamic till removing search head. After removal you can again make static captain.

0 Karma

deepashri_123
Motivator

Hi danielwan,

Please refer to the document below:

https://docs.splunk.com/Documentation/Splunk/7.0.1/DistSearch/Removeaclustermember
Hope this helps!!!!

0 Karma

danielwan
Explorer

I have already followed the document.
The error message seems to mean that I am using static captain than dynamical captain, so splunk remove shcluster-member does not work here.

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...