Deployment Architecture

Is there a CLI command to enable or disable serach peers in Splunk 6.3.1?

basanthp
Path Finder

I have added the PROD and DR indexer hosts using add search-server CLI command. Now my requirement is to keep the PROD indexers as enabled and DR indexers as disabled. Is there a CLI command to achieve this? Do I need to disable via UI only?

0 Karma

renjith_nair
Legend

You can remove a search peer using web or CLI

splunk remove search-server -auth admin:password -url 10.10.10.10:8089

http://docs.splunk.com/Documentation/Splunk/6.2.0/DistSearch/Removeasearchpeer

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

basanthp
Path Finder

@Renjith, I am aware of the add and remove CLI commands. But my requirement is to enable or disable the search peers which has been added already. During Active-Passive switchover, I will disable the active peers and enable the passive peers (like we do in the UI -> Distributed Search -> search peers option).

0 Karma

renjith_nair
Legend

Normally for all operations from web, there should be CLI as well as configuration parameter available in splunk.

Are you looking for

splunk disable dist-search -auth admin:password

Sorry I don't have a splunk env to test it now.

./splunk help distributed
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...