My Splunk environment contains 1 master 6 pears of indexer hosts. I just want to perform the CUP upgrade on my indexer hosts which all are in virtual environment. i Need to reboot the virtual system after CUP upgrade.
whats the best practices to do this on all 6 indexer pears by minimizing the downtime.
i had resolved it, in 3 steps.
1.updated restart_timeout stanza, increased time out to 15 min in master server server.conf file( master will wait for the peer node to come up till 15 min )
2 set the peer node offline using 'splunk offline'
3 power off the peer node
4 Change the HW settings
5 power on the system
6 wait for replication and search factors met on the master server dashboard
Hi, you should post your answers as an answer and mark it as "resolved"... so people can see the result better 🙂
For any sort of planned maintenance on your indexer cluster consider using maintenance mode; this way you can prevent bucket fixups from happening in the event that something doesn't come back up in time, etc.