Deployment Architecture

In Search Head Clustering, what splunkd.log entries will show when an instance may have been the captain or member?

Ellen
Splunk Employee
Splunk Employee

I know I can run the following to get the current SHC captain,

splunk show shcluster-status -auth <username>:<password>

but for debugging, what text can I search for to see the sequence of the dynamic captain change over time in my SHC instances?

1 Solution

Ellen
Splunk Employee
Splunk Employee

In splunkd.log

To verify if the SHC instance is functioning as a captain or member during a timeline, look for these entries:

    Captain:

    10-05-2015 00:13:06.524 +0000 INFO  SHPRaftConsensus - Now leader for term 16
    10-05-2015 00:13:06.524 +0000 INFO  SHPoolingMgr - Making node the captain
    10-05-2015 00:13:06.526 +0000 INFO  SHPoolingMgr - makeOrChangeSlave - master_shp = https://splunk-search-head-cluster-node20:8089

    Member :

    10-05-2015 00:13:06.600 +0000 INFO  SHPRaftConsensus - All hail leader https://splunk-search-head-cluster-node20:8089 for term 16
    10-05-2015 00:13:06.708 +0000 INFO  SHPoolingMgr - makeOrChangeSlave - master_shp = https://splunk-search-head-cluster-node20:8089

View solution in original post

Ellen
Splunk Employee
Splunk Employee

In splunkd.log

To verify if the SHC instance is functioning as a captain or member during a timeline, look for these entries:

    Captain:

    10-05-2015 00:13:06.524 +0000 INFO  SHPRaftConsensus - Now leader for term 16
    10-05-2015 00:13:06.524 +0000 INFO  SHPoolingMgr - Making node the captain
    10-05-2015 00:13:06.526 +0000 INFO  SHPoolingMgr - makeOrChangeSlave - master_shp = https://splunk-search-head-cluster-node20:8089

    Member :

    10-05-2015 00:13:06.600 +0000 INFO  SHPRaftConsensus - All hail leader https://splunk-search-head-cluster-node20:8089 for term 16
    10-05-2015 00:13:06.708 +0000 INFO  SHPoolingMgr - makeOrChangeSlave - master_shp = https://splunk-search-head-cluster-node20:8089

hexx
Splunk Employee
Splunk Employee

I would also suggest to use the Search-Head Clustering views of the Distributed Management Console to this effect. Notably, the "General Status & Configuration" view shows a history of recent captain elections.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...