Running on Splunk 6.4.2 Can someone tell me proper procedures to update the RHEL7 OS, as to limit Splunk downtime?
We have a clustered environment a master/deployment server, 4 indexers, 1 ES search head and 1 heavy forwarder (for syslog). We have kernel updates, w/several rpm pkg updates as well. We need to update the servers and reboot and I am not sure of the procedure to make sure we do it properly and not to lose ingestion. I saw in Answers how to move master to maintenance in an earlier version, but couldn't find anything on this newer version.
This should work for you :
On another note, if you want to reduce downtime in future, upgrade your search head also to a search head cluster and also add another HF for load balancing the syslog( if it's direct tcp)