Getting Data In

Indexer cluster Hardware upgradation

svemurilv
Path Finder

Hi,
My Splunk environment contains 1 master 6 pears of indexer hosts. I just want to perform the CUP upgrade on my indexer hosts which all are in virtual environment. i Need to reboot the virtual system after CUP upgrade.
whats the best practices to do this on all 6 indexer pears by minimizing the downtime.

-Rag

Tags (3)
0 Karma
1 Solution

svemurilv
Path Finder

i had resolved it, in 3 steps.
1.updated restart_timeout stanza, increased time out to 15 min in master server server.conf file( master will wait for the peer node to come up till 15 min )
2 set the peer node offline using 'splunk offline'
3 power off the peer node
4 Change the HW settings
5 power on the system
6 wait for replication and search factors met on the master server dashboard

View solution in original post

0 Karma

svemurilv
Path Finder

i had resolved it, in 3 steps.
1.updated restart_timeout stanza, increased time out to 15 min in master server server.conf file( master will wait for the peer node to come up till 15 min )
2 set the peer node offline using 'splunk offline'
3 power off the peer node
4 Change the HW settings
5 power on the system
6 wait for replication and search factors met on the master server dashboard

0 Karma

jtacy
Builder

For any sort of planned maintenance on your indexer cluster consider using maintenance mode; this way you can prevent bucket fixups from happening in the event that something doesn't come back up in time, etc.
https://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Usemaintenancemode

0 Karma

hsesterhenn
Path Finder

Hi, you should post your answers as an answer and mark it as "resolved"... so people can see the result better 🙂
Holger

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...