Getting Data In

How to disable a search peer via the CLI or REST API call?

tsunamii
Path Finder

Hi Splunkers,

Is there a way to disable a search peer via the CLI or an API call?

Specifically, I would like to set this param via CLI or REST API, and without having to restart splunk:

# distsearch.conf
disabled_servers = <comma separated list of servers>
* A list of configured but disabled search peers.

Thanks.

0 Karma
1 Solution

splunkIT
Splunk Employee
Splunk Employee

I have tested the following commands in my 6.3.3 search head, and appears to be working:

To enable search peer:

curl -ku admin https://<host>:<mPort>/servicesNS/-/search/search/distributed/peers/<search_peer_host>%3A<mPort>/ena... -X POST

To disable search peer:

curl -ku admin https://<host>:<mPort>/servicesNS/-/search/search/distributed/peers/<search_peer_host>%3A<mPort>/dis... -X POST

View solution in original post

splunkIT
Splunk Employee
Splunk Employee

I have tested the following commands in my 6.3.3 search head, and appears to be working:

To enable search peer:

curl -ku admin https://<host>:<mPort>/servicesNS/-/search/search/distributed/peers/<search_peer_host>%3A<mPort>/ena... -X POST

To disable search peer:

curl -ku admin https://<host>:<mPort>/servicesNS/-/search/search/distributed/peers/<search_peer_host>%3A<mPort>/dis... -X POST
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...