Deployment Architecture

Remove closed search heads in our splunk cluster Or Master

anil1432
Explorer

 

Hello EveryOne ,

Please Help Me Regarding How to Remove Splunk Search heads From Splunk Master Or Cluster

 

We Have Some Splunk Dedicated Search Heads  In Our Environment. Ex: 15 Search Heads . In That 7 Search Heads Are Down, Because The Users Are Stopped Using Splunk Search Heads. . So Now We Are Planning To Remove Those 7 search  heads from our Splunk Master . What Is Procedure . could Anyone Explain Me In Manual Way. It Would Be Great. .

 

Please Also Check One Screen Shot I Have Shared . Find Below , We Need to Remove These Search Heads.

 

 

RegardsScreenshot 2021-10-28 at 2.33.39 PM.png

Labels (1)
0 Karma

anil1432
Explorer

Hello @isoutamo  ,

Could You Please Provide me The Step By Step Document To Remove Search Heads From Splunk Master . It  Would Be Very Helpful To me please 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

If it's still inSHC, then remove it from there: https://docs.splunk.com/Documentation/Splunk/8.2.3/DistSearch/Removeaclustermember

Remove "search peer" (your SHC member from MC/CM acting as MC): https://docs.splunk.com/Documentation/Splunk/8.2.3/DistSearch/Removeasearchpeer

Then update MC's inventory:

Settings -> MC -> General Setup -> Apply Changes

Then it should be ok.

r. Ismo

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @anil1432 

search heads must have been clustered to use this link. This has detailed steps, Master/Manager used in indexers world. Where as Search heads having captain. Captain doesn't play a role in removing the member as per steps above.

https://docs.splunk.com/Documentation/Splunk/8.2.2/DistSearch/Removeaclustermember

 

--

An upvote would be appreciated if this reply helps!

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

If you refer Monitoring Console as a cluster master, then just remove those indexer peers from Distributed search and then apply new config on MC's settings pages.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...