I have added the PROD and DR indexer hosts using add search-server CLI command. Now my requirement is to keep the PROD indexers as enabled and DR indexers as disabled. Is there a CLI command to achieve this? Do I need to disable via UI only?
You can remove a search peer using web or CLI
splunk remove search-server -auth admin:password -url 10.10.10.10:8089
http://docs.splunk.com/Documentation/Splunk/6.2.0/DistSearch/Removeasearchpeer
@Renjith, I am aware of the add and remove CLI commands. But my requirement is to enable or disable the search peers which has been added already. During Active-Passive switchover, I will disable the active peers and enable the passive peers (like we do in the UI -> Distributed Search -> search peers option).
Normally for all operations from web, there should be CLI as well as configuration parameter available in splunk.
Are you looking for
splunk disable dist-search -auth admin:password
Sorry I don't have a splunk env to test it now.
./splunk help distributed