Hi,
My Splunk environment contains 1 master 6 pears of indexer hosts. I just want to perform the CUP upgrade on my indexer hosts which all are in virtual environment. i Need to reboot the virtual system after CUP upgrade.
whats the best practices to do this on all 6 indexer pears by minimizing the downtime.
-Rag
i had resolved it, in 3 steps.
1.updated restart_timeout stanza, increased time out to 15 min in master server server.conf file( master will wait for the peer node to come up till 15 min )
2 set the peer node offline using 'splunk offline'
3 power off the peer node
4 Change the HW settings
5 power on the system
6 wait for replication and search factors met on the master server dashboard
i had resolved it, in 3 steps.
1.updated restart_timeout stanza, increased time out to 15 min in master server server.conf file( master will wait for the peer node to come up till 15 min )
2 set the peer node offline using 'splunk offline'
3 power off the peer node
4 Change the HW settings
5 power on the system
6 wait for replication and search factors met on the master server dashboard
For any sort of planned maintenance on your indexer cluster consider using maintenance mode; this way you can prevent bucket fixups from happening in the event that something doesn't come back up in time, etc.
https://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Usemaintenancemode
Hi, you should post your answers as an answer and mark it as "resolved"... so people can see the result better 🙂
Holger