Getting Data In

Indexer cluster Hardware upgradation

svemurilv
Path Finder

Hi,
My Splunk environment contains 1 master 6 pears of indexer hosts. I just want to perform the CUP upgrade on my indexer hosts which all are in virtual environment. i Need to reboot the virtual system after CUP upgrade.
whats the best practices to do this on all 6 indexer pears by minimizing the downtime.

-Rag

Tags (3)
0 Karma
1 Solution

svemurilv
Path Finder

i had resolved it, in 3 steps.
1.updated restart_timeout stanza, increased time out to 15 min in master server server.conf file( master will wait for the peer node to come up till 15 min )
2 set the peer node offline using 'splunk offline'
3 power off the peer node
4 Change the HW settings
5 power on the system
6 wait for replication and search factors met on the master server dashboard

View solution in original post

0 Karma

svemurilv
Path Finder

i had resolved it, in 3 steps.
1.updated restart_timeout stanza, increased time out to 15 min in master server server.conf file( master will wait for the peer node to come up till 15 min )
2 set the peer node offline using 'splunk offline'
3 power off the peer node
4 Change the HW settings
5 power on the system
6 wait for replication and search factors met on the master server dashboard

0 Karma

jtacy
Builder

For any sort of planned maintenance on your indexer cluster consider using maintenance mode; this way you can prevent bucket fixups from happening in the event that something doesn't come back up in time, etc.
https://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Usemaintenancemode

0 Karma

hsesterhenn
Path Finder

Hi, you should post your answers as an answer and mark it as "resolved"... so people can see the result better 🙂
Holger

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...