Deployment Architecture

Search Head Cluster member removal

coreyf311
Path Finder

How can I remove a search head cluster member when that member is down? Power outage at a location took down two of our search head cluster members for a week. I cant push bundles from the Deployer while these two are down. How can I remove them from the cluster while they are down so that the rest of the cluster can operate as intended?

1 Solution

coreyf311
Path Finder

we have majority. The SHC in total is 6 SH's. So we currently have 4 SH's up and available and 2 that are down and unavailable.

0 Karma

somesoni2
Revered Legend

I'm guessing you can't deploy because you lost majority for captain election. In cases like this, you'd assign one of available node as static captain so that SHC can function. See this for more info on how to do it.

http://docs.splunk.com/Documentation/Splunk/7.0.3/DistSearch/Staticcaptain

0 Karma

p_gurav
Champion

coreyf311
Path Finder

does not work because the member i am trying to remove is not available. its down due to a power outage in the DC it is hosted.

0 Karma

def65483
Explorer

How is this the accepted answer? It does not explain at all the process to remove an already downed member from a cluster. If I missed it, please explain.

Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...