Deployment Architecture

Search Head Cluster member removal

coreyf311
Path Finder

How can I remove a search head cluster member when that member is down? Power outage at a location took down two of our search head cluster members for a week. I cant push bundles from the Deployer while these two are down. How can I remove them from the cluster while they are down so that the rest of the cluster can operate as intended?

1 Solution

coreyf311
Path Finder

we have majority. The SHC in total is 6 SH's. So we currently have 4 SH's up and available and 2 that are down and unavailable.

0 Karma

somesoni2
Revered Legend

I'm guessing you can't deploy because you lost majority for captain election. In cases like this, you'd assign one of available node as static captain so that SHC can function. See this for more info on how to do it.

http://docs.splunk.com/Documentation/Splunk/7.0.3/DistSearch/Staticcaptain

0 Karma

p_gurav
Champion

coreyf311
Path Finder

does not work because the member i am trying to remove is not available. its down due to a power outage in the DC it is hosted.

0 Karma

def65483
Explorer

How is this the accepted answer? It does not explain at all the process to remove an already downed member from a cluster. If I missed it, please explain.

Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...