Deployment Architecture

I screwed up my search head cluster. How can I remove the nodes and re-establish the SH cluster again?

splunkIT
Splunk Employee
Splunk Employee

I have 3 search head cluster nodes in my test env. I won't go into details on how I broke the SH cluster. I would like to know how to reinitialize the nodes and re-establishing the SH cluster again. Thanks in advance for your advice.

Tags (1)

rbal_splunk
Splunk Employee
Splunk Employee

You can perform following steps to re-initialize the Search head Cluster.

1) Stop the Splunk Service for all Search Head Cluster Nodes.
2) Clear _raft folder from each SH Cluster ($SPLUNK_HOME/ var/run/splunk/_raft)
3) Start Splunk Service
4) Re-Initialize the Search Head Cluster Member using command below. Command provided in Splunk Documentation
5) Bootstrap SH Cluster Members - Command provided in Splunk Documentation

sk314
Builder

It would be better if we knew why you think you broke it. perhaps.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...