Deployment Architecture

Search head clustering

neovenkat
Explorer

We have search head cluster with 3 SHs. The search head replication factor is set to 2. We are facing an issue when the scheduled reports are ran in the 3rd search head which does not have the replicated artifacts. Note this (3rd) search head was added to the cluster recently. Could please let us know if we are missing any configuration so that this issue does not occur

0 Karma

kartm2020
Communicator

Hi Neovenkat,

I think this is due to replication factor. Setting the replication in search head clustering is optional. I have the same environment as like yours. If you see below server.conf, i haven't set the rep factor.
Please remove rep factor and do the splunk restart and try again. I hope it will work.

server.conf:

[shclustering]
conf_deploy_fetch_url = https://XX.XX.XX.XX:8089
disabled = 0
mgmt_uri = https://XX.XX.XX.XX:8089
pass4SymmKey = *****
shcluster_label = shcluster1
id = ****

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...