Running on Splunk 6.4.2 Can someone tell me proper procedures to update the RHEL7 OS, as to limit Splunk downtime?
We have a clustered environment a master/deployment server, 4 indexers, 1 ES search head and 1 heavy forwarder (for syslog). We have kernel updates, w/several rpm pkg updates as well. We need to update the servers and reboot and I am not sure of the procedure to make sure we do it properly and not to lose ingestion. I saw in Answers how to move master to maintenance in an earlier version, but couldn't find anything on this newer version.